CVE-2023-50251

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-50251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-50251
Aliases
Related
Published
2023-12-12T21:15:08Z
Modified
2024-09-18T03:14:28.532757Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a use tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

References

Affected packages

Debian:12 / php-dompdf-svg-lib

Package

Name
php-dompdf-svg-lib
Purl
pkg:deb/debian/php-dompdf-svg-lib?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-3+deb12u1

Affected versions

0.*

0.5.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / php-dompdf-svg-lib

Package

Name
php-dompdf-svg-lib
Purl
pkg:deb/debian/php-dompdf-svg-lib?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.1-1

Affected versions

0.*

0.5.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/dompdf/php-svg-lib

Affected ranges

Type
GIT
Repo
https://github.com/dompdf/php-svg-lib
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.3.4
0.4.0
0.4.1
0.5.0

v0.*

v0.1
v0.2
v0.3
v0.3.0
v0.3.1
v0.3.2
v0.3.3