CVE-2021-21236

NameCVE-2021-21236
DescriptionCairoSVG is a Python (pypi) package. CairoSVG is an SVG converter base ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs979597

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cairosvg (PTS)bullseye2.5.0-1.1+deb11u2fixed
bullseye (security)2.5.0-1.1+deb11u1fixed
bookworm2.5.2-1.1+deb12u1fixed
trixie2.7.1-2fixed
forky, sid2.9.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cairosvgsourcestretch(not affected)
cairosvgsourcebuster(not affected)
cairosvgsource(unstable)2.5.0-1.1979597

Notes

[buster] - cairosvg <not-affected> (Vulnerable code introduced in 2.0.0rc6)
[stretch] - cairosvg <not-affected> (Vulnerable code introduced in 2.0.0rc6)
https://github.com/Kozea/CairoSVG/security/advisories/GHSA-hq37-853p-g5cf
Introduced by: https://github.com/Kozea/CairoSVG/commit/4f14d2e8f2d7f9b534c5342e26519b7c27386a81
Fixed by: https://github.com/Kozea/CairoSVG/commit/063185b60588a41d4df661ad70f9f7b699901abc (2.5.1)

Search for package or bug name: Reporting problems