Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45729

Опубликовано: 01 июн. 2026
Источник: debian

Описание

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thorvgfixed1.0.6+dfsg-1package

Примечания

  • https://github.com/thorvg/thorvg/security/advisories/GHSA-f863-8ghq-7h64

  • https://github.com/thorvg/thorvg/pull/4387

  • Fixed by: https://github.com/thorvg/thorvg/commit/159f44fd5e3d2eea1b3a70689a894e657e2bb079

  • Fixed by: https://github.com/thorvg/thorvg/commit/599db59600aefab904fc8465bd86ac29e1de168c (v1.0.5)

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5.

CVSS3: 4.3
nvd
2 месяца назад

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5.