The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg prior to 2.40.7 allows context-dependent malicious users to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnome librsvg |