PT-2016-5895 · Gnome+1 · Librsvg+1

Brian May

·

Publicado

2014-03-18

·

Atualizado

2018-10-30

·

CVE-2016-4348

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions librsvg version 2.40.2
Description The issue allows context-dependent attackers to cause a denial of service, resulting in stack consumption and application crash, via circular definitions in an SVG document. This occurs due to the rsvg css normalize font size function.
Recommendations For librsvg version 2.40.2, consider updating to a newer version that addresses this issue, as the current version allows for a denial of service attack through specifically crafted SVG documents. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1310
CVE-2016-4348
DLA-477-1
DSA-3584-1

Produtos afetados

Alt Linux
Librsvg