Lucene search

K
redosRedosROS-20230911-09
HistorySep 11, 2023 - 12:00 a.m.

ROS-20230911-09

2023-09-1100:00:00
redos.red-soft.ru
6
xml
vulnerability
merge
librsvg
path restriction
unauthorized access
exploit
vector graphics
rendering library

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%

A vulnerability in the XML document merge mechanism XInclude of the vector graphics rendering library librsvg
is related to incorrect restriction of path name to restricted directory when processing element
xi:include. Exploitation of the vulnerability may allow an intruder to gain unauthorized access to the protected information.
protected information.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64librsvg2<= 2.50.0-4UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%