Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000041

Опубликовано: 07 июн. 2018
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.

Отчет

The described vulnerability only affects librsvg on Windows, where UNC path references can lead to the NTLM hash being leaked.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5librsvg2Not affected
Red Hat Enterprise Linux 6librsvg2Not affected
Red Hat Enterprise Linux 7librsvg2Not affected
Red Hat Enterprise Linux 8librsvg2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1588840librsvg: Improper input validation vulnerability in rsvg-io.c

EPSS

Процентиль: 70%
0.00645
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.

CVSS3: 8.8
nvd
почти 8 лет назад

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.

CVSS3: 8.8
debian
почти 8 лет назад

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd52 ...

suse-cvrf
больше 7 лет назад

Security update for librsvg

suse-cvrf
больше 7 лет назад

Security update for librsvg

EPSS

Процентиль: 70%
0.00645
Низкий

4.7 Medium

CVSS3