VDB

GCVE-VVD-MAGEIA-2023-259

GCVE-VVD-MAGEIA-2023-259
Advisory Published
Vulnetix · Advisory published September 11, 2023
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element. (CVE-2023-38633)

Affected Products

VendorProductVersionsPlatforms
Mageialibrsvg0 (affected), 2.56.0-1.1.mga9 (unaffected)
Mageialibrsvg0 (affected), 2.50.3-1.2.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›