#1033295 cairosvg: CVE-2023-27586: SSRF & DOS vulnerability

Package:
src:cairosvg
Source:
src:cairosvg
Submitter:
Salvatore Bonaccorso
Date:
2023-04-07 10:06:15 UTC
Severity:
normal
Tags:
#1033295#5
Date:
2023-03-21 19:40:17 UTC
From:
To:
Hi,

The following vulnerability was published for cairosvg.

CVE-2023-27586[0]:
| CairoSVG is an SVG converter based on Cairo, a 2D graphics library.
| Prior to version 2.7.0, Cairo can send requests to external hosts when
| processing SVG files. A malicious actor could send a specially crafted
| SVG file that allows them to perform a server-side request forgery or
| denial of service. Version 2.7.0 disables CairoSVG's ability to access
| other files online by default.

I am planning to look in the current bullseye version for a security
upload, and can have a look as well for doing a NMU reaching bookworm.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-27586
https://www.cve.org/CVERecord?id=CVE-2023-27586
[1] https://github.com/Kozea/CairoSVG/security/advisories/GHSA-rwmf-w63j-p7gv
[2] https://github.com/Kozea/CairoSVG/commit/12d31c653c0254fa9d9853f66b04ea46e7397255

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1033295#12
Date:
2023-03-22 19:54:13 UTC
From:
To:
Dear maintainer,

I've prepared an NMU for cairosvg (versioned as 2.5.2-1.1) and
uploaded it to DELAYED/2. Please feel free to tell me if I
should delay it longer.

Regards,
Salvatore

#1033295#21
Date:
2023-03-24 20:49:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
cairosvg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1033295@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated cairosvg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 21 Mar 2023 22:21:22 +0100
Source: cairosvg
Architecture: source
Version: 2.5.2-1.1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1033295
Changes:
 cairosvg (2.5.2-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * Don't allow fetching external files unless explicitly asked for
     (CVE-2023-27586) (Closes: #1033295)
Checksums-Sha1:
 9eee07166b362867758176bcfaccff3aabc5d932 2386 cairosvg_2.5.2-1.1.dsc
 d658cf2fb7e4568d12395f398287118662acd507 7476 cairosvg_2.5.2-1.1.debian.tar.xz
 8c26072b312ab916d94c379f77daf648e8ffb4f4 7660 cairosvg_2.5.2-1.1_source.buildinfo
Checksums-Sha256:
 6a03414f49ef1c5759f3684b714d1a4e1e48f0beda615c1c917cc4d96163ab06 2386 cairosvg_2.5.2-1.1.dsc
 e0350298a5192caab517cc163b1cff49ca943ffe2586eea117147df92d79a066 7476 cairosvg_2.5.2-1.1.debian.tar.xz
 1615f488b79aa3b5f7173b22a99eb275c41f054476dc63ffb151e518564dee5c 7660 cairosvg_2.5.2-1.1_source.buildinfo
Files:
 2b7b138b383ef8792650335a948fdf55 2386 python optional cairosvg_2.5.2-1.1.dsc
 34313bc23b7da763c59aec36a342d3e0 7476 python optional cairosvg_2.5.2-1.1.debian.tar.xz
 c631befbf5f527cd4ed628446b065544 7660 python optional cairosvg_2.5.2-1.1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmQbWHBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EuzEP/j4dmBflFYxEtJuO4trlc+n+aE8ZqE+J
DNQoX8HoU2Bjg9l8Pgiv9FUAEYGPrh/xwjQArCjqPCCfZUsT6aYlxM1x4TI3eE00
fyUuug/M78kbfyvCReIHOgf7luD0LJW1+wxggPLsWmqm/q7g9eH7CkAv98Npa+7b
DzdrbLKvXQSyv4c2gxcb729MAXqfpmyQKiCHuk1RQOb3WQGBmH2h6e9DeWkkNj3C
J2tPl28ay8BOy+u8XGUI7prhGhBnaptysscJoJg1kTJ+gariYaejYukZq06oE1j1
zvRZsbXk+xDA+LLRJ0mnrJcuB4lIs77t7XwsI/bqmaB4atmC6lMRmMpKc4s/nlQF
WegoVUXZEMLTnnsNwfuS7YCqrH16ltX8TZ9OVhF1K5T8cSxWigm1Y61zru7tgaX/
2LgHDLp4xAC+bFUcG6/xMV3OernOUvVUgaSVfFjkT04C5b7dqQrx9tyc7omjRW5l
AkiimFosbJqquaxqmSlsQApX7LKd8wHtI3Y9dN/RoHXFOqvCmTvMjedMAXHKFLxq
OncCNO7Uj7BBSsqfQNl7NROsNuNrXu1J2IaJVJjpgDpBETJy6GbiagtS/S5vDHVM
zwmyXhRXukncB4IRfWsXLJTxMUm/qephp7t0WgabLW5zG00PJU/fNaGmw9pl6fbl
awiYXwbWQG3F
=a0oZ
-----END PGP SIGNATURE-----

#1033295#26
Date:
2023-04-07 10:02:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
cairosvg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1033295@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated cairosvg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 23 Mar 2023 20:51:51 +0100
Source: cairosvg
Architecture: source
Version: 2.5.0-1.1+deb11u1
Distribution: bullseye-security
Urgency: high
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1033295
Changes:
 cairosvg (2.5.0-1.1+deb11u1) bullseye-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Don't allow fetching external files unless explicitly asked for
     (CVE-2023-27586) (Closes: #1033295)
Checksums-Sha1:
 6dafb710f0e598b2ad145e058950f646eeba681b 2397 cairosvg_2.5.0-1.1+deb11u1.dsc
 12a1e41cef6167f7e207ca6d128fe39ee46f0158 8340610 cairosvg_2.5.0.orig.tar.gz
 9c4f5e448f74931af7413728ec01746a3e5bdb18 7992 cairosvg_2.5.0-1.1+deb11u1.debian.tar.xz
 353c64eefc0894ce2b463af02c67e26cca23c0b7 7692 cairosvg_2.5.0-1.1+deb11u1_source.buildinfo
Checksums-Sha256:
 fb962bb09f09dbbaebb2c2205e3bb97e93e050b2ac13078d87a14574cb035799 2397 cairosvg_2.5.0-1.1+deb11u1.dsc
 1560c66c119a1f74348293f484be4aef837b9691502c228e5e0f4824a0b6dfa5 8340610 cairosvg_2.5.0.orig.tar.gz
 69d2e1ea6934de434af38355e8186b6d72a4ceb2e517b03190db9e3e664e620d 7992 cairosvg_2.5.0-1.1+deb11u1.debian.tar.xz
 ae18d2d715d923e9bb3707e0456c5a4bb99f2d98bb5fa29e9c3024b6c3996680 7692 cairosvg_2.5.0-1.1+deb11u1_source.buildinfo
Files:
 633383b28b5c6209e492211a078ea4af 2397 python optional cairosvg_2.5.0-1.1+deb11u1.dsc
 08fafc33e0f747b9240558e4865af3e9 8340610 python optional cairosvg_2.5.0.orig.tar.gz
 aede5f5ba2213942aafb0d687ebb88ac 7992 python optional cairosvg_2.5.0-1.1+deb11u1.debian.tar.xz
 89d81645ccd59a846d68520808bf5cea 7692 python optional cairosvg_2.5.0-1.1+deb11u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmQcrn1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EAuwP/jIyIL+pqxZXcBWdxZD9EgBSgGmEjLQp
QasYSX6PzKR50ndriotx0lr0eiy6NLjGibu8VekYyXhdQVDej2c2kRqQAuBED1Ei
p1PoNt0bbeCehiaWeIRxC67As1HNtvNO4g+CvsnRArqq/NamIUvA22ClGRtK9NVT
WBbocAZUw2YuRQwZ8/CbRPNH3USUjTunCzc03XhV5aZoxSpW6lqJoV0G5o6EM51R
DUTXNPP6Kx0/Eki0czYoGAjElbgWK2MysV1UKsumK2mtZllw/GxoVWJdT0C/qrTm
e9ev6+7koJLYgM+Fn4ziPcTeS7fqV/73JKSWV7SwL2wfRb8ul55PqoF1RWiiNiWP
Ooq98VOCxaeV/Y4vEbIYYA2YkrAOAQ3ZPoZfy4WnRpzSzZCTSIvc5ZgF/wQIlg3/
k5peat6pvI7G0KYwg60qzzHH0JvrnDSUx0X86EUdXES3jraCnCVo14RzYDh8GEEd
k9+Y36jtge41OcSfhAVoeX+IVUqrxCXEdTZPF1B7mujyIyZTCdY+Tpk6ZGTcbGkv
ZD5N9oLDVCRC5G4n2Il16g3S+m0KMNsVtpbFPpUQ4tcrMHgANe4QrCq2ocQE8z/I
pY32Rot8me+YFdA4hyiGqGqDEBUAxqcn49xDkzEPlc7kmPa0pjlyuRbHVNkZid76
VNuFUUFJ3vAv
=X8KN
-----END PGP SIGNATURE-----