Summary: | <gnome-base/librsvg-2.40.21: Resource exhaustion via crafted SVG file with nested patterns (CVE-2019-20446) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | gnome |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://gitlab.gnome.org/GNOME/librsvg/issues/515 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
gnome-base/librsvg-2.40.21
|
Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
![]() In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially. amd64 stable x86 stable sparc stable s390 stable ia64 stable ppc64 stable ppc stable hppa stable arm stable arm64 stable, cleanup done GLSA Vote: No Repository is clean, all done! |