SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
irradiated@radiation.partyMB to TechNews@radiation.party · 2 years ago

[HN] When URL parsers disagree (CVE-2023-38633, librsvg)

www.canva.dev

external-link
message-square
0
fedilink
  • cross-posted to:
  • rust@programming.dev
  • hackernews@lemmy.smeargle.fans
  • hackernews@derp.foo
  • netsec@lemmy.world
1
external-link

[HN] When URL parsers disagree (CVE-2023-38633, librsvg)

www.canva.dev

irradiated@radiation.partyMB to TechNews@radiation.party · 2 years ago
message-square
0
fedilink
  • cross-posted to:
  • rust@programming.dev
  • hackernews@lemmy.smeargle.fans
  • hackernews@derp.foo
  • netsec@lemmy.world
When URL parsers disagree (CVE-2023-38633) - Canva Engineering Blog
www.canva.dev
external-link
Discovery and walkthrough of CVE-2023-38633 in librsvg, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.

[ comments | sourced from HackerNews ]

alert-triangle
You must log in or register to comment.

TechNews@radiation.party

technews@radiation.party

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technews@radiation.party
lock
Community locked: only moderators can create posts. You can still comment on posts.

Aggregated tech news.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 9 users / 6 months
  • 89 local subscribers
  • 4.39K subscribers
  • 18K Posts
  • 7.31K Comments
  • Modlog
  • mods:
  • andrew@radiation.party
  • irradiated@radiation.party
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org