Mageia 2019-0160: svgsalamander security update
Summary
A vulnerability was found in the svgsalamander library. If the library is
being used in a web application for processing user supplied SVG files then
the app is vulnerable to SSRF (CVE-2017-5617).
References
- https://bugs.mageia.org/show_bug.cgi?id=24592
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UPUOI6NCEB6H6YHKN7M4V3CAQD63NXAU/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5617
Resolution
MGASA-2019-0160 - Updated svgsalamander packages fix security vulnerability
SRPMS
- 6/core/svgsalamander-1.1.2-1.mga6