PT-2016-5895 · Gnome+1 · Librsvg+1

Brian May

·

Published

2014-03-18

·

Updated

2018-10-30

·

CVE-2016-4348

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions librsvg version 2.40.2
Description The issue allows context-dependent attackers to cause a denial of service, resulting in stack consumption and application crash, via circular definitions in an SVG document. This occurs due to the rsvg css normalize font size function.
Recommendations For librsvg version 2.40.2, consider updating to a newer version that addresses this issue, as the current version allows for a denial of service attack through specifically crafted SVG documents. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1310
CVE-2016-4348
DLA-477-1
DSA-3584-1

Affected Products

Alt Linux
Librsvg