Bug#1041810: librsvg: CVE-2023-38633

2023-08-27 Thread Salvatore Bonaccorso
Hi Simon, On Sat, Aug 19, 2023 at 06:57:30PM +0200, Salvatore Bonaccorso wrote: > Hi Simon, > > On Sun, Jul 30, 2023 at 09:48:57PM +0100, Simon McVittie wrote: > > On Sun, 30 Jul 2023 at 22:04:24 +0200, Salvatore Bonaccorso wrote: > > > For bullseye I think we should simply pick the upstream

Bug#1041810: librsvg: CVE-2023-38633

2023-08-19 Thread Simon McVittie
On Sat, 19 Aug 2023 at 18:57:29 +0200, Salvatore Bonaccorso wrote: > If you are happy with the results and coverage from unstable, would > you be open to prepare/finalize next the respective updates for > bookworm-security and bullseye-security? I already had them in what I believe to be an

Bug#1041810: librsvg: CVE-2023-38633

2023-08-19 Thread Salvatore Bonaccorso
Hi Simon, On Sun, Jul 30, 2023 at 09:48:57PM +0100, Simon McVittie wrote: > On Sun, 30 Jul 2023 at 22:04:24 +0200, Salvatore Bonaccorso wrote: > > For bullseye I think we should simply pick the upstream commit? > > Yes: we didn't keep up with upstream 2.50.x so there are a bunch of > unrelated

Bug#1041810: librsvg: CVE-2023-38633

2023-07-30 Thread Simon McVittie
On Sun, 30 Jul 2023 at 22:04:24 +0200, Salvatore Bonaccorso wrote: > For bullseye I think we should simply pick the upstream commit? Yes: we didn't keep up with upstream 2.50.x so there are a bunch of unrelated fixes (2.50.4 up to .7) which would be out of scope for a security update. If it was a

Bug#1041810: librsvg: CVE-2023-38633

2023-07-30 Thread Salvatore Bonaccorso
Hi Simon, On Sun, Jul 30, 2023 at 04:07:50PM +0100, Simon McVittie wrote: > On Sun, 23 Jul 2023 at 21:13:38 +0200, Salvatore Bonaccorso wrote: > > The following vulnerability was published for librsvg. > > > > CVE-2023-38633[0]: > > | A directory traversal problem in the URL decoder of librsvg

Bug#1041810: librsvg: CVE-2023-38633

2023-07-30 Thread Simon McVittie
On Sun, 23 Jul 2023 at 21:13:38 +0200, Salvatore Bonaccorso wrote: > The following vulnerability was published for librsvg. > > CVE-2023-38633[0]: > | A directory traversal problem in the URL decoder of librsvg before > | 2.56.3 could be used by local or remote attackers to disclose files > | (on

Bug#1041810: librsvg: CVE-2023-38633

2023-07-23 Thread Salvatore Bonaccorso
Source: librsvg Version: 2.54.5+dfsg-3 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/librsvg/-/issues/996 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for librsvg. CVE-2023-38633[0]: | A directory