Lucene search

K
redosRedosROS-20230411-01
HistoryApr 11, 2023 - 12:00 a.m.

ROS-20230411-01

2023-04-1100:00:00
redos.red-soft.ru
46
cairosvg vulnerability
svg file processing
remote attacker
sensitive data access
local network
malicious requests
vulnerable server
unix

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

EPSS

0.001

Percentile

38.6%

The CairoSVG SVG converter vulnerability is related to insufficient validation of user input during the
SVG file processing. Exploitation of the vulnerability could allow an attacker acting remotely,
access sensitive data located on a local network or send malicious requests to other servers from a vulnerable server.
requests to other servers from a vulnerable system.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64python3-cairosvg< 2.7.0-1UNKNOWN

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

EPSS

0.001

Percentile

38.6%