{"id":"openSUSE-SU-2023:0260-1","summary":"Security update for python-CairoSVG","details":"This update for python-CairoSVG fixes the following issues:\n\n- CVE-2023-27586: Don't allow fetching external files unless explicitly asked for. (boo#1209538)\n\n- Update to version 2.5.2\n\n  * Fix marker path scale\n\n- Update to version 2.5.1 (boo#1180648, CVE-2021-21236):\n\n  * Security fix: When processing SVG files, CairoSVG was using two\n    regular expressions which are vulnerable to Regular Expression \n    Denial of Service (REDoS). If an attacker provided a malicious \n    SVG, it could make CairoSVG get stuck processing the file for a \n    very long time.\n  * Fix marker positions for unclosed paths\n  * Follow hint when only output_width or output_height is set\n  * Handle opacity on raster images\n  * Don’t crash when use tags reference unknown tags\n  * Take care of the next letter when A/a is replaced by l\n  * Fix misalignment in node.vertices\n\n- Updates for version 2.5.0.\n\n  * Drop support of Python 3.5, add support of Python 3.9.\n  * Add EPS export\n  * Add background-color, negate-colors, and invert-images options\n  * Improve support for font weights\n  * Fix opacity of patterns and gradients\n  * Support auto-start-reverse value for orient\n  * Draw images contained in defs\n  * Add Exif transposition support\n  * Handle dominant-baseline\n  * Support transform-origin\n","modified":"2026-03-11T07:33:30.129750Z","published":"2023-09-25T12:02:25Z","related":["CVE-2021-21236","CVE-2023-27586"],"upstream":["CVE-2021-21236","CVE-2023-27586"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GIY4HBHI7WUBHUAMEZKWBMEPOUYNCTU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180648"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209538"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-27586"}],"affected":[{"package":{"name":"python-CairoSVG","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/python-CairoSVG&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-bp155.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"python3-CairoSVG":"2.5.2-bp155.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0260-1.json"}},{"package":{"name":"python-CairoSVG","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/python-CairoSVG&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-bp155.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"python3-CairoSVG":"2.5.2-bp155.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0260-1.json"}}],"schema_version":"1.7.5"}