ZeroHour

CVE-2019-20446

CVSS 3.1
6.5 medium
EPSS
2%p81
Published
()
Modified
Description

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Vendors
gnomeopensusefedoraprojectdebiancanonicalnetapp
Products
librsvg, leap, fedora, debian linux, ubuntu linux, active iq unified manager
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.