Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 486600 (CVE-2013-1881) - <gnome-base/librsvg-2.36.4-r1: XML External Entities Information Disclosure Vulnerability (CVE-2013-1881)
Summary: <gnome-base/librsvg-2.36.4-r1: XML External Entities Information Disclosure V...
Status: RESOLVED FIXED
Alias: CVE-2013-1881
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/55088/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-09-30 18:42 UTC by Agostino Sarubbo
Modified: 2013-12-03 19:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-09-30 18:42:08 UTC
From ${URL} :

Description

Positive Technologies has reported a vulnerability in librsvg, which can be exploited by malicious 
people to potentially disclose sensitive information.

The vulnerability is caused due to an error when parsing XML entities, which can potentially be 
exploited to e.g. disclose contents of certain local files by tricking a user into opening a 
specially crafted XML document including external entity references.

The vulnerability is reported in versions prior to 2.39.


Solution:
Update to version 2.39.

Provided and/or discovered by:
Timur Yunusov and Alexey Osipov, Positive Technologies.

Original Advisory:
librsvg:
http://ftp.gnome.org/pub/GNOME/sources/librsvg/2.39/librsvg-2.39.0.changes

PT-2013-01:
http://en.securitylab.ru/lab/PT-2013-01


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Alexandre Rostovtsev (RETIRED) gentoo-dev 2013-10-01 17:58:11 UTC
+*librsvg-2.36.4-r1 (01 Oct 2013)
+
+  01 Oct 2013; Alexandre Rostovtsev <tetromino@gentoo.org>
+  +librsvg-2.36.4-r1.ebuild, -librsvg-2.37.0.ebuild,
+  +files/librsvg-2.36.4-resource-uri-1.patch,
+  +files/librsvg-2.36.4-resource-uri-2.patch,
+  +files/librsvg-2.36.4-resource-uri-3.patch:
+  Fix information disclosure vulnerability (CVE-2013-1881, bug #486600, thanks
+  to Agostino Sarubbo). Drop vulnerable version.

Thanks for letting us know; fixed in 2.36.4-r1 and 2.39.0

=gnome-base/librsvg-2.36.4-r1 should be stabilized.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2013-10-03 00:48:53 UTC
Arches, please test and mark stable:                                                                                                           
=gnome-base/librsvg-2.36.4-r1                                                                                  
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2013-10-03 14:21:12 UTC
Stable for HPPA.
Comment 4 Agostino Sarubbo gentoo-dev 2013-10-05 06:19:21 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-10-06 07:51:27 UTC
x86 stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-10-06 10:12:44 UTC
ia64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-10-06 15:19:15 UTC
alpha stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-10-07 19:30:10 UTC
ppc stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-10-09 11:16:46 UTC
arm stable
Comment 10 Agostino Sarubbo gentoo-dev 2013-10-09 11:18:43 UTC
ppc64 stable
Comment 11 Agostino Sarubbo gentoo-dev 2013-10-09 17:09:48 UTC
sparc stable
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2013-10-16 02:03:38 UTC
CVE-2013-1881 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1881):
  GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files
  via an XML document containing an external entity declaration in conjunction
  with an entity reference, related to an XML External Entity (XXE) issue.
Comment 13 Sergey Popov gentoo-dev 2013-11-28 08:58:08 UTC
Thanks, everyone

GLSA vote: no
Comment 14 Chris Reffett (RETIRED) gentoo-dev Security 2013-12-03 19:28:08 UTC
GLSA vote: no. Closing noglsa.