Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whvx-2m69-j66g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

EPSS

Процентиль: 80%
0.01495
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
redhat
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
nvd
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
debian
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nest ...

suse-cvrf
больше 5 лет назад

Security update for librsvg

EPSS

Процентиль: 80%
0.01495
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400