9.8
CVSSv3

CVE-2023-50252

Published: 12/12/2023 Updated: 15/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially when the `href` attribute from the `<use>` tag has not been sanitized. This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. Version 0.5.1 contains a patch for this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

dompdf php-svg-lib

Vendor Advisories

Debian Bug report logs - #1058641 php-dompdf-svg-lib: CVE-2023-50251 CVE-2023-50252 Package: src:php-dompdf-svg-lib; Maintainer for src:php-dompdf-svg-lib is Debian PHP PEAR Maintainers &lt;pkg-php-pear@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Wed, 13 Dec 2023 21:48:01 UTC Se ...
Check Point Reference: CPAI-2023-1668 Date Published: 24 Apr 2024 Severity: Critical ...