CVE-2019-20446

Name
CVE-2019-20446
Description
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://gitlab.gnome.org/GNOME/librsvg/issues/515
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.html
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
Mailing List https://lists.debian.org/debian-lts-announce/2020/07/msg00016.html
Third Party Advisory https://usn.ubuntu.com/4436-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:* librsvg >= None < 2.40.21
cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:* librsvg >= 2.42.0 < 2.42.8
cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:* librsvg >= 2.44.0 < 2.44.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
librsvg 3.10-main 2.40.21-r0 Natanael Copa <ncopa@alpinelinux.org> fixed