ZeroHour

CVE-2016-4348

CVSS 3.0
7.5 high
EPSS
2%p83
Published
()
Modified
Description

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.

Vendors
gnomedebianopensuse
Products
librsvg, debian linux, leap, opensuse
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.