Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:9DB0274DC8606DE258D54EF9A66D487D
HistoryAug 16, 2023 - 12:00 a.m.

USN-6266-1: librsvg vulnerability | Cloud Foundry

2023-08-1600:00:00
Cloud Foundry
www.cloudfoundry.org
4
remote code execution
update instructions
cve-2023-38633
cloud foundry
mitigation
cflinuxfs4
cf deployment

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%

Severity

Medium

Vendor

Canonical Ubuntu

Versions Affected

  • Canonical Ubuntu 22.04

Description

Zac Sims discovered that librsvg incorrectly handled decoding URLs. A remote attacker could possibly use this issue to read arbitrary files by using an include element. Update Instructions: Run sudo pro fix USN-6266-1 to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: librsvg2-common – 2.48.9-1ubuntu0.20.04.4 gir1.2-rsvg-2.0 – 2.48.9-1ubuntu0.20.04.4 librsvg2-doc – 2.48.9-1ubuntu0.20.04.4 librsvg2-bin – 2.48.9-1ubuntu0.20.04.4 librsvg2-2 – 2.48.9-1ubuntu0.20.04.4 librsvg2-dev – 2.48.9-1ubuntu0.20.04.4 No subscription required

CVEs contained in this USN include: CVE-2023-38633.

Affected Cloud Foundry Products and Versions

Severity is medium unless otherwise noted.

  • cflinuxfs4
    • All versions prior to 1.27.0
  • CF Deployment
    • All versions prior to 32.0.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • cflinuxfs4
    • Upgrade all versions to 1.27.0 or greater
  • CF Deployment
    • Upgrade all versions to 32.0.0 or greater

References

History

2023-08-16: Initial vulnerability report published.

Affected configurations

Vulners
Node
cloudfoundrygorouterRange<1.27.0
OR
cloudfoundrycf-deploymentRange<32.0.0
CPENameOperatorVersion
cflinuxfs4lt1.27.0
cf deploymentlt32.0.0

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%