Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-27586
HistoryMar 20, 2023 - 4:15 p.m.

CVE-2023-27586

2023-03-2016:15:13
Debian Security Bug Tracker
security-tracker.debian.org
21
cairosvg
svg converter
security update
ssrf
dos
vulnerability
cairo
2d graphics
library
version 2.7.0
online access
file processing

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

EPSS

0.001

Percentile

38.6%

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG’s ability to access other files online by default.

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

EPSS

0.001

Percentile

38.6%