Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7557

Опубликовано: 20 мая 2016
Источник: debian
EPSS Низкий

Описание

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librsvgfixed2.40.9-2package
librsvgfixed2.40.5-1+deb8u1jessiepackage
librsvgfixed2.36.1-2+deb7u1wheezypackage

Примечания

  • https://bugzilla.gnome.org/show_bug.cgi?id=738050 (not public accessible)

  • https://git.gnome.org/browse/librsvg/commit/rsvg-shapes.c?id=40af93e6eb1c94b90c3b9a0b87e0840e126bb8df (2.40.7)

EPSS

Процентиль: 66%
0.00518
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

redhat
почти 10 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
nvd
больше 9 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
github
больше 3 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

EPSS

Процентиль: 66%
0.00518
Низкий