Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1187489 > unrolled thread
| Started by | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| First post | 2024-02-25 21:30 +0100 |
| Last post | 2024-03-07 07:10 +0100 |
| Articles | 2 — 1 participant |
Back to article view | Back to linux.debian.bugs.dist
Bug#1064781: php-dompdf-svg-lib: CVE-2024-25117 Salvatore Bonaccorso <carnil@debian.org> - 2024-02-25 21:30 +0100
Bug#1064781: Accepted php-dompdf-svg-lib 0.5.2-1 (source) into unstable Salvatore Bonaccorso <carnil@debian.org> - 2024-03-07 07:10 +0100
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-02-25 21:30 +0100 |
| Subject | Bug#1064781: php-dompdf-svg-lib: CVE-2024-25117 |
| Message-ID | <Ibtih-cByW-17@gated-at.bofh.it> |
Source: php-dompdf-svg-lib
Version: 0.5.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Hi,
The following vulnerability was published for php-dompdf-svg-lib.
CVE-2024-25117[0]:
| php-svg-lib is a scalable vector graphics (SVG) file
| parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails
| to validate that font-family doesn't contain a PHAR url, which might
| leads to RCE on PHP < 8.0, and doesn't validate if external
| references are allowed. This might leads to bypass of restrictions
| or RCE on projects that are using it, if they do not strictly
| revalidate the fontName that is passed by php-svg-lib. The
| `Style::fromAttributes(`), or the `Style::parseCssStyle()` should
| check the content of the `font-family` and prevents it to use a PHAR
| url, to avoid passing an invalid and dangerous `fontName` value to
| other libraries. The same check as done in the
| `Style::fromStyleSheets` might be reused. Libraries using this
| library as a dependency might be vulnerable to some bypass of
| restrictions, or even remote code execution, if they do not double
| check the value of the `fontName` that is passed by php-svg-lib.
| Version 0.5.2 contains a fix for this issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-25117
https://www.cve.org/CVERecord?id=CVE-2024-25117
[1] https://github.com/dompdf/php-svg-lib/security/advisories/GHSA-f3qr-qr4x-j273
[2] https://github.com/dompdf/php-svg-lib/commit/732faa9fb4309221e2bd9b2fda5de44f947133aa
[3] https://github.com/dompdf/php-svg-lib/commit/8ffcc41bbde39f09f94b9760768086f12bbdce42
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-03-07 07:10 +0100 |
| Subject | Bug#1064781: Accepted php-dompdf-svg-lib 0.5.2-1 (source) into unstable |
| Message-ID | <Iff73-eY2t-1@gated-at.bofh.it> |
| In reply to | #1187489 |
Source: php-dompdf-svg-lib Source-Version: 0.5.2-1 This addresses as well #1064781. On Wed, Mar 06, 2024 at 10:23:06PM +0000, Debian FTP Masters wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > Format: 1.8 > Date: Wed, 06 Mar 2024 22:47:59 +0100 > Source: php-dompdf-svg-lib > Architecture: source > Version: 0.5.2-1 > Distribution: unstable > Urgency: medium > Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org> > Changed-By: William Desportes <williamdes@wdes.fr> > Changes: > php-dompdf-svg-lib (0.5.2-1) unstable; urgency=medium > . > * New upstream version 0.5.2 > - Fixes validation vulnerability CVE-2024-25117 > Checksums-Sha1: > d8b5ecc5665000abb1fb0fa6f36f5b51a7ca426a 2195 php-dompdf-svg-lib_0.5.2-1.dsc > 46c119d7dc7a47c2c868073b73b2dedc2d3eb942 57040 php-dompdf-svg-lib_0.5.2.orig.tar.xz > 192337d493164b3ef2452cfcde5940ac69ff1dd0 2904 php-dompdf-svg-lib_0.5.2-1.debian.tar.xz > 62b6c8c4a6565bfc188af4a5316b39759fc25f77 10065 php-dompdf-svg-lib_0.5.2-1_source.buildinfo > Checksums-Sha256: > 2fb4e92bcd3e3a18d9eca9d58fa8fe94912e2152b90431ec21867b0873c2f103 2195 php-dompdf-svg-lib_0.5.2-1.dsc > ecad76e01a6d553b254721132a41eec524130f0e68e5e4f7ca82e4184f2abddf 57040 php-dompdf-svg-lib_0.5.2.orig.tar.xz > 34276aff6270a1faf256edb9a8118d889d76e023eb51b62166c1d97b6cac6f05 2904 php-dompdf-svg-lib_0.5.2-1.debian.tar.xz > a34ff961c6b93ad2bff9083d11a8671c188db4b092227546939100444ceeaaa6 10065 php-dompdf-svg-lib_0.5.2-1_source.buildinfo > Files: > 30540889f8cc8655d5f6e887fc96bf98 2195 php optional php-dompdf-svg-lib_0.5.2-1.dsc > 2c1bb8d8e57d360bdc83c1e866f043cf 57040 php optional php-dompdf-svg-lib_0.5.2.orig.tar.xz > 98a8bd4dc556b21407ba51ef57d56192 2904 php optional php-dompdf-svg-lib_0.5.2-1.debian.tar.xz > 1e7ab1da9f326d16b5200a8581fa57f6 10065 php optional php-dompdf-svg-lib_0.5.2-1_source.buildinfo > > -----BEGIN PGP SIGNATURE----- > > iQIzBAEBCgAdFiEExNkf3872tKPGU/14kKDvG4JRqIkFAmXo6J0ACgkQkKDvG4JR > qImVpQ/+K8Zdo3k4Pb50tqRIgRW5Q1Y6v0aklM+OOygpMVinAFHoDErhYafo6/iT > iEPoB64D00JOS5bIVeemX5JOvRiN1zqGE/grEBiprKNzJTjFqDs7sMhmOXEjV56v > jzRu4loONDOrznMw7T9PZYJ0qwbys0SPSPBk2cya18CoNv+6JqXLn/5KFzVrhSTQ > 8SRb9JoxZGrwXiXpanty7NHDo+QPgEp4KfOkvAtPkJ+HGy/OagtqjfVtcs1vTivC > x1pdtnaCZr0cl7Mz1SYHlfsVR6kc6HvtW4bc/aVvqKiSQg4IZC2uNtmEnJcXztqp > ImwsmWhntuV730DCQxZCDNuKGhplEoY8QCGPPZvY82MpUdpzAqPi1bz2Uunlljj1 > 09yp4BGvAiTftc/obsnN0+iGxz8oovA6nTEqjb6kuTZFWg+MyQTfVgU7zwYvvX09 > i0SQa2dqtVupeYELArq6z69J0d1kCe5CCZ0dTPfWIjkrI34SmDE3JU7W7NhKuneR > 35mLEMM+9FahE+fDveBbEQuXNx3OcmO+614VV7wJxjwS/GIrdMRleP6AIiNDFtJD > SSGJJRjFBFjb9ye5RKRruJ1WdsWIfrVKjnd4sLBowNW0ZDJCVfvKWy4XQIvDhjJX > ZhJUxBfyTEzgtLUmtRzb8/MEQi2kSu+DvfEZijcF7Rk6rmZKvHk= > =O5Js > -----END PGP SIGNATURE-----
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web