383
VMScore

CVE-2019-20446

Published: 02/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In xml.rs in GNOME librsvg prior to 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome librsvg

opensuse leap 15.1

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

netapp active iq unified manager -

Vendor Advisories

Synopsis Moderate: librsvg2 security update Type/Severity Security Advisory: Moderate Topic An update for librsvg2 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...