CVE-2019-20446

Description

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.33

Associated Vulnerability

VulnerabilityOS Platform
renderer library for SVG files (USN-4436-1) librsvg2-2_2.40.13-3ubuntu0.1_i386.debLinux
renderer library for SVG files (USN-4436-1) librsvg2-2_2.40.13-3ubuntu0.1_amd64.debLinux
renderer library for SVG files (USN-4436-1) librsvg2-2_2.40.20-2ubuntu0.1_i386.debLinux
renderer library for SVG files (USN-4436-1) librsvg2-2_2.40.20-2ubuntu0.1_amd64.debLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-2.42.7-4.el8.i686.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-2.42.7-4.el8.x86_64.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-debugsource-2.42.7-4.el8.i686.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-debugsource-2.42.7-4.el8.x86_64.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-devel-2.42.7-4.el8.i686.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-devel-2.42.7-4.el8.x86_64.rpmLinux
(RHSA-2020:4709) librsvg2 security update librsvg2-tools-2.42.7-4.el8.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) gdk-pixbuf-loader-rsvg-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) gdk-pixbuf-loader-rsvg-debuginfo-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) librsvg-2-2-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) librsvg-2-2-32bit-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) librsvg-2-2-debuginfo-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) librsvg-2-2-debuginfo-32bit-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) librsvg-debugsource-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) rsvg-view-2.40.21-5.9.1.x86_64.rpmLinux
SUSE-SU-2020:0604-1(SUSE Linux Enterprise Server 12-SP5 ) rsvg-view-debuginfo-2.40.21-5.9.1.x86_64.rpmLinux
(RHSA-2020:4709)Moderate: security update librsvg2-debuginfo-2.42.7-4.el8.i686.rpmLinux
(RHSA-2020:4709)Moderate: security update librsvg2-debuginfo-2.42.7-4.el8.x86_64.rpmLinux
(RHSA-2020:4709)Moderate: security update librsvg2-tools-debuginfo-2.42.7-4.el8.i686.rpmLinux
(RHSA-2020:4709)Moderate: security update librsvg2-tools-debuginfo-2.42.7-4.el8.x86_64.rpmLinux
librsvg2 security update (RLSA-2020:4709) librsvg2-2.42.7-4.el8.i686.rpmLinux
librsvg2 security update (RLSA-2020:4709) librsvg2-2.42.7-4.el8.x86_64.rpmLinux
librsvg2 security update (RLSA-2020:4709) librsvg2-devel-2.42.7-4.el8.i686.rpmLinux
librsvg2 security update (RLSA-2020:4709) librsvg2-devel-2.42.7-4.el8.x86_64.rpmLinux
librsvg2 security update (RLSA-2020:4709) librsvg2-tools-2.42.7-4.el8.x86_64.rpmLinux
Librsvg2 update (ELSA-2020-4709) librsvg2-2.42.7-4.el8.i686.rpmLinux
Librsvg2 update (ELSA-2020-4709) librsvg2-2.42.7-4.el8.x86_64.rpmLinux
Librsvg2-devel update (ELSA-2020-4709) librsvg2-devel-2.42.7-4.el8.i686.rpmLinux
Librsvg2-devel update (ELSA-2020-4709) librsvg2-devel-2.42.7-4.el8.x86_64.rpmLinux
Librsvg2-tools update (ELSA-2020-4709) librsvg2-tools-2.42.7-4.el8.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234