VYPR

apk package

chainguard/snappy

pkg:apk/chainguard/snappy

Vulnerabilities (2)

  • CVE-2023-41330Sep 6, 2023
    affected < 0fixed 0

    knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2 add

  • CVE-2023-28115Mar 17, 2023
    affected < 0fixed 0

    Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can