openSUSE-SU-2023:0272-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0272-1
openSUSE-SU-2023:0272-1
Summary: Security update for python-CairoSVG
Details: This update for python-CairoSVG fixes the following issues: - CVE-2023-27586: Don't allow fetching external files unless explicitly asked for. (boo#1209538) - Update to version 2.5.2 * Fix marker path scale - Update to version 2.5.1 (boo#1180648, CVE-2021-21236): * Security fix: When processing SVG files, CairoSVG was using two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provided a malicious SVG, it could make CairoSVG get stuck processing the file for a very long time. * Fix marker positions for unclosed paths * Follow hint when only output_width or output_height is set * Handle opacity on raster images * Don’t crash when use tags reference unknown tags * Take care of the next letter when A/a is replaced by l * Fix misalignment in node.vertices - Updates for version 2.5.0. * Drop support of Python 3.5, add support of Python 3.9. * Add EPS export * Add background-color, negate-colors, and invert-images options * Improve support for font weights * Fix opacity of patterns and gradients * Support auto-start-reverse value for orient * Draw images contained in defs * Add Exif transposition support * Handle dominant-baseline * Support transform-origin
References: https://lists.opensuse.org/archives/list/[email protected]/thread/74KEOEJKIQ5UHFG7M5KN7X37WT37PVYX/, https://bugzilla.suse.com/1180648, https://bugzilla.suse.com/1209538, https://www.suse.com/security/cve/CVE-2021-21236, https://www.suse.com/security/cve/CVE-2023-27586
Affected packages
Package
Name: python-CairoSVG
Purl: pkg:rpm/suse/python-CairoSVG&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
