Opened 21 months ago

Closed 21 months ago

Last modified 20 months ago

#18327 closed enhancement (fixed)

librsvg-2.56.3

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.0
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version

Change History (6)

comment:1 by Xi Ruoyao, 21 months ago

Priority: normalelevated

Version 2.56.3

This is a security release for bug #996.

  • #996 - Fix arbitrary file read when href has special characters.
  • #998 - Fix cascade for symbol elements being referenced from use elements.

comment:2 by Xi Ruoyao, 21 months ago

The sed for test is no longer needed.

comment:3 by Douglas R. Reno, 21 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:4 by Douglas R. Reno, 21 months ago

The security vulnerability has been assigned CVE-2023-38633, and a proof-of-concept is in the Github issue that reads /etc/passwd: https://gitlab.gnome.org/GNOME/librsvg/-/issues/996

comment:5 by Douglas R. Reno, 21 months ago

Resolution: fixed
Status: assignedclosed

Fixed at a2ada4045db8c85cdcfc71c1802cdee3adb20ffa

SA-11.3-063 issued.

comment:6 by Bruce Dubbs, 20 months ago

Milestone: 11.412.0

Milestone renamed

Note: See TracTickets for help on using tickets.