🐈.md (22)

←← 掲示板一覧に戻る ← スレッド一覧に戻る

14 野に咲く名無し@転載禁止 () 2023/09/05 23:46:21

When URL parsers disagree (CVE-2023-38633)
https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/

Discovery and walkthrough of CVE-2023-38633 in librsvg, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.