6.8
CVSSv2

CVE-2011-3146

Published: 05/09/2012 Updated: 13/09/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 607
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

librsvg prior to 2.34.1 uses the node name to identify the type of node, which allows context-dependent malicious users to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome librsvg

Vendor Advisories

SVG image rendering library has had flaws fixed ...