445
VMScore

CVE-2016-4348

Published: 20/05/2016 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent malicious users to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome librsvg

debian debian linux 8.0

opensuse opensuse 13.2

opensuse leap 42.1

Vendor Advisories

Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions A remote attacker can take advantage of these flaws to cause an application using the librsvg library to crash For the stable distribution (jessie), these problems have been fixed in version 2405-1+d ...
The _rsvg_css_normalize_font_size function in librsvg 2402 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document ...