HomeDefectsLIN1022-4841
Fixed

LIN1022-4841 : Security Advisory - librsvg - CVE-2023-38633

Created: Jul 23, 2023    Updated: Oct 9, 2023
Resolved Date: Oct 9, 2023
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CREATE(Triage):(User=admin) CVE-2023-38633 (https://nvd.nist.gov/vuln/detail/CVE-2023-38633)