librsvg 2.48.9-1ubuntu0.20.04.4 source package in Ubuntu

Changelog

librsvg (2.48.9-1ubuntu0.20.04.4) focal-security; urgency=medium

  * SECURITY UPDATE: Arbitrary file read when xinclude href has special
    characters
    - debian/patches/CVE-2023-38633.patch: validate URLs in
      librsvg/rsvg-handle.c, rsvg_internals/src/allowed_url.rs,
      rsvg_internals/src/filters/component_transfer.rs, tests/*.
    - debian/patches/fix_old_rust_compat.patch: fix compatibility with
      older rust versions in rsvg_internals/src/allowed_url.rs.
    - CVE-2023-38633
  * Don't fail the build on tests error for i386

 -- Marc Deslauriers <email address hidden>  Fri, 28 Jul 2023 08:56:58 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates main libdevel
Focal security main libdevel

Downloads

File Size SHA-256 Checksum
librsvg_2.48.9.orig.tar.xz 12.1 MiB 357f3fdebd78c563c7ab27da9116f03b781fca78808b4ac3cb7e4e3ed5ea3968
librsvg_2.48.9-1ubuntu0.20.04.4.debian.tar.xz 27.4 KiB 7b2e1968df7f65481e3caba65bd4d2e7c7eed1ad7629daa0021dcc622740302d
librsvg_2.48.9-1ubuntu0.20.04.4.dsc 3.0 KiB 43fcc4a024c8248fb126240512d35404e356e0dad240ac44076b50a0919e573e

View changes file

Binary packages built by this source

gir1.2-rsvg-2.0: gir files for renderer library for SVG files

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package contains GObject-Introspection information.

librsvg2-2: SAX-based renderer library for SVG files (runtime)

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package contains the runtime library, necessary to run
 applications using librsvg.

librsvg2-2-dbgsym: debug symbols for librsvg2-2
librsvg2-bin: command-line utility to convert SVG files

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package includes a command-line utility to convert the SVG files
 to the PNG format.

librsvg2-bin-dbgsym: debug symbols for librsvg2-bin
librsvg2-common: SAX-based renderer library for SVG files (extra runtime)

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package includes the gdk-pixbuf loader allowing
 to load SVG images transparently inside GTK+ applications.

librsvg2-common-dbgsym: debug symbols for librsvg2-common
librsvg2-dev: SAX-based renderer library for SVG files (development)

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package provides the necessary development libraries and include
 files to allow you to develop with librsvg.

librsvg2-doc: SAX-based renderer library for SVG files (documentation)

 The rsvg library is an efficient renderer for Scalable Vector Graphics
 (SVG) pictures.
 .
 This package provides the API documentation.