Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-38633
Description:A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.1.2023.5484   1.3.6.1.4.1.25623.1.1.12.2023.6266.1   1.3.6.1.4.1.25623.1.1.10.2023.0259   1.3.6.1.4.1.25623.1.0.884665   1.3.6.1.4.1.25623.1.1.2.2023.3012   1.3.6.1.4.1.25623.1.1.4.2023.3208.1   1.3.6.1.4.1.25623.1.0.833887   1.3.6.1.4.1.25623.1.1.2.2023.3035   1.3.6.1.4.1.25623.1.0.884612  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-38633
Debian Security Information: DSA-5484 (Google Search)
https://www.debian.org/security/2023/dsa-5484
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R5BCXT5GW6RCL45ZUHUZR4CJG2BAFDVC/
http://seclists.org/fulldisclosure/2023/Jul/43
https://bugzilla.suse.com/show_bug.cgi?id=1213502
https://gitlab.gnome.org/GNOME/librsvg/-/issues/996
https://news.ycombinator.com/item?id=37415799
https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/
http://www.openwall.com/lists/oss-security/2023/07/27/1
http://www.openwall.com/lists/oss-security/2023/09/06/10




© 1998-2025 E-Soft Inc. All rights reserved.