Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20446

Опубликовано: 02 фев. 2020
Источник: debian
EPSS Низкий

Описание

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librsvgfixed2.46.4-1package
librsvgfixed2.44.10-2.1+deb10u1busterpackage
librsvgno-dsajessiepackage

Примечания

  • https://gitlab.gnome.org/GNOME/librsvg/issues/515

  • https://gitlab.gnome.org/GNOME/librsvg/commit/572f95f739529b865e2717664d6fefcef9493135

EPSS

Процентиль: 80%
0.01495
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
redhat
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
nvd
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

suse-cvrf
больше 5 лет назад

Security update for librsvg

suse-cvrf
почти 5 лет назад

Security update for librsvg

EPSS

Процентиль: 80%
0.01495
Низкий