Debian Security Update DSA-5382 cairosvg - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,935
Reaction score
80
Credits
-1,257
It was reported that cairosvg, a SVG converter based on Cairo, can send requests to external hosts when processing specially crafted SVG files with external file resource loading. An attacker can take advantage of this flaw to perform a server-side request forgery or denial of service. Fetching of external files is disabled by default with this update.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top