Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20446

Опубликовано: 02 фев. 2020
Источник: redhat
CVSS3: 6.5

Описание

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Отчет

This flaw is similar to billion laughs. A specially-crafted XML file can cause librsvg to consume excessive memory and result in denial of service. This flaw also affects browsers. Currently Mozilla and Google are working on updates for Firefox and Chromium browser respectively.

Меры по смягчению последствий

This flaw is triggered when untrusted XML files are parsed with applications compiled with librsvg2 library. Applications which do not parse untrusted XML files are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5librsvg2Out of support scope
Red Hat Enterprise Linux 6chromium-browserOut of support scope
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6librsvg2Out of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7firefoxWill not fix
Red Hat Enterprise Linux 7librsvg2Will not fix
Red Hat Enterprise Linux 7thunderbirdWill not fix
Red Hat Enterprise Linux 8firefoxWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1797608librsvg: Resource exhaustion via crafted SVG file with nested patterns

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
nvd
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
debian
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nest ...

suse-cvrf
больше 5 лет назад

Security update for librsvg

suse-cvrf
почти 5 лет назад

Security update for librsvg

6.5 Medium

CVSS3