UbuntuUpdates.org

Package "librsvg2-doc"

Name: librsvg2-doc

Description:

SAX-based renderer library for SVG files (documentation)

Latest version: 2.54.5+dfsg-1ubuntu2.1
Release: lunar (23.04)
Level: updates
Repository: main
Head package: librsvg
Homepage: https://wiki.gnome.org/Projects/LibRsvg

Links


Download "librsvg2-doc"


Other versions of "librsvg2-doc" in Lunar

Repository Area Version
base main 2.54.5+dfsg-1ubuntu2
security main 2.54.5+dfsg-1ubuntu2.1

Changelog

Version: 2.54.5+dfsg-1ubuntu2.1 2023-08-01 15:07:10 UTC

  librsvg (2.54.5+dfsg-1ubuntu2.1) lunar-security; urgency=medium

  * SECURITY UPDATE: Arbitrary file read when xinclude href has special
    characters
    - debian/patches/CVE-2023-38633.patch: validate URLs in
      include/librsvg/rsvg.h, src/error.rs, src/lib.rs,
      src/url_resolver.rs, tests/*.
    - CVE-2023-38633

 -- Marc Deslauriers <email address hidden> Fri, 28 Jul 2023 08:51:09 -0400

CVE-2023-38633 A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local



About   -   Send Feedback to @ubuntu_updates