Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-20446

Опубликовано: 02 фев. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.46.4-1ubuntu1
eoan

ignored

end of life
esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

see notes
esm-infra/focal

not-affected

2.48.7-1ubuntu0.20.04.1
esm-infra/xenial

ignored

see notes
focal

not-affected

2.48.7-1ubuntu0.20.04.1
groovy

not-affected

2.46.4-1ubuntu1
hirsute

not-affected

2.46.4-1ubuntu1

Показывать по

EPSS

Процентиль: 80%
0.01495
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
nvd
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVSS3: 6.5
debian
больше 5 лет назад

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nest ...

suse-cvrf
больше 5 лет назад

Security update for librsvg

suse-cvrf
почти 5 лет назад

Security update for librsvg

EPSS

Процентиль: 80%
0.01495
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3