File _patchinfo of Package patchinfo.41873
<patchinfo incident="41873"> <issue tracker="cve" id="2024-12224"/> <issue tracker="cve" id="2024-43806"/> <issue tracker="bnc" id="1229950">VUL-0: CVE-2024-43806: librsvg: rustix: rustix::fs::Dir iterator with the linux_raw backend can cause memory explosion</issue> <issue tracker="bnc" id="1243867">VUL-0: CVE-2024-12224: librsvg: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded</issue> <packager>federico-mena</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for librsvg</summary> <description>This update for librsvg fixes the following issues: Update to version 2.52.12. - CVE-2024-12224: idna: incorrect hostname comparisons and URL parsing may be performed due to acceptance of Punycode labels that do not produce any non-ASCII output when decoded (bsc#1243867). - CVE-2024-43806: rustix: unbounded memory explosion leading to an application OOM crash when using the `rustix::fs::Dir` iterator with the `linux_raw` backend (bsc#1229950). </description> </patchinfo>