Medium severity5.5NVD Advisory· Published Jul 22, 2023· Updated Jun 17, 2026
CVE-2023-38633
CVE-2023-38633
Description
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33<2.56.3+ 1 more
- (no CPE)range: <2.56.3
- cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*range: >=2.42.3,<2.46.6
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- librsvg/librsvgdescription
- osv-coords26 versionspkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/opensuse/librsvg&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/librsvg&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/librsvg&distro=SUSE%20Manager%20Server%204.2pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/librsvg&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/almalinux/librsvg2pkg:rpm/almalinux/librsvg2-develpkg:rpm/almalinux/librsvg2-toolspkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/opensuse/librsvg&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/librsvg&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/librsvg&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/librsvg&distro=SUSE%20Manager%20Proxy%204.2
< 2.52.10-150400.3.6.1+ 25 more
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.50.7-1.el9_2.1
- (no CPE)range: < 2.50.7-1.el9_2.1
- (no CPE)range: < 2.50.7-1.el9_2.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.52.10-150400.3.6.1
- (no CPE)range: < 2.46.7-150200.3.9.1
- (no CPE)range: < 2.46.7-150200.3.9.1
Patches
Vulnerability mechanics
References
12- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2023/07/27/1nvdExploitMailing ListThird Party Advisory
- gitlab.gnome.org/GNOME/librsvg/-/issues/996nvdExploitIssue TrackingVendor Advisory
- www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/nvdExploitTechnical DescriptionThird Party Advisory
- seclists.org/fulldisclosure/2023/Jul/43nvdMailing ListNot ApplicableThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5BCXT5GW6RCL45ZUHUZR4CJG2BAFDVC/nvdThird Party Advisory
- news.ycombinator.com/itemnvdIssue TrackingThird Party Advisory
- security.netapp.com/advisory/ntap-20230831-0011/nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5484nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2023/09/06/10nvdMailing List
- gitlab.gnome.org/GNOME/librsvg/-/releases/2.56.3nvdRelease Notes
News mentions
0No linked articles in our index yet.