VYPR

rpm package

suse/python-CairoSVG&distro=SUSE Package Hub 15 SP5

pkg:rpm/suse/python-CairoSVG&distro=SUSE%20Package%20Hub%2015%20SP5

Vulnerabilities (2)

  • CVE-2023-27586Mar 20, 2023
    affected < 2.5.2-bp155.3.3.1fixed 2.5.2-bp155.3.3.1

    CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or

  • CVE-2021-21236Jan 6, 2021
    affected < 2.5.2-bp155.3.3.1fixed 2.5.2-bp155.3.3.1

    CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are