VYPR

rpm package

opensuse/python-CairoSVG&distro=openSUSE Leap 15.4

pkg:rpm/opensuse/python-CairoSVG&distro=openSUSE%20Leap%2015.4

Vulnerabilities (2)

  • CVE-2023-27586Mar 20, 2023
    affected < 2.5.2-bp154.2.3.1fixed 2.5.2-bp154.2.3.1

    CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or

  • CVE-2021-21236Jan 6, 2021
    affected < 2.5.2-bp154.2.3.1fixed 2.5.2-bp154.2.3.1

    CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are