GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Mar 14, 2020 5:26 pm Post subject: [ GLSA 202003-11 ] SVG Salamander |
|
|
Gentoo Linux Security Advisory
Title: SVG Salamander: Server-Side Request Forgery (GLSA 202003-11)
Severity: normal
Exploitable: remote
Date: 2020-03-14
Bug(s): #607720
ID: 202003-11
Synopsis
A SSRF may allow remote attackers to forge illegitimate requests.
Background
SVG Salamander is a light weight SVG renderer and animator for Java.
Affected Packages
Package: dev-java/svgsalamander
Vulnerable: <= 0.0-r2
Architectures: All supported architectures
Description
A Server-Side Request Forgery was discovered in SVG Salamander.
Impact
An attacker, by sending a specially crafted SVG file, can conduct SSRF.
Workaround
There is no known workaround at this time.
Resolution
Gentoo has discontinued support for SVG Salamander. We recommend that
users unmerge SVG Salamander:
Code: | # emerge --unmerge "dev-java/svgsalamander"
|
References
CVE-2017-5617 |
|