Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 902491 - <media-gfx/cairosvg-2.7.0: fetches arbitrary resources from SVG files by default
Summary: <media-gfx/cairosvg-2.7.0: fetches arbitrary resources from SVG files by default
Status: CONFIRMED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 902493
Blocks:
  Show dependency tree
 
Reported: 2023-03-21 05:36 UTC by Michał Górny
Modified: 2023-03-22 06:38 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2023-03-21 05:36:09 UTC
+Version 2.7.0 released on 2023-03-20
+====================================
+
+**WARNING:** this is a security update.
+
+When processing SVG files, CairoSVG could access other files online, possibly
+leading to very long renderings or other security problems.
+
+This feature is now disabled by default. External resources can still be
+accessed using the "unsafe" or the "url_fetcher" parameter.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2023-03-22 06:23:06 UTC
cleanup done.