First published: Wed Aug 31 2011(Updated: )
A NULL pointer dereference flaw was reported [1] by Sauli Pahlman in librsvg. If a program linked to librsvg where to open a crafted SVG file, it could cause that application to crash or potentially execute arbitrary code. [1] <a href="https://launchpad.net/bugs/825497">https://launchpad.net/bugs/825497</a> <a href="https://bugzilla.gnome.org/show_bug.cgi?id=658014">https://bugzilla.gnome.org/show_bug.cgi?id=658014</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/librsvg | <2.34.1 | 2.34.1 |
CentOS Librsvg2 | <=2.34.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3146 has been classified as a high severity vulnerability due to its potential for causing application crashes and executing arbitrary code.
To fix CVE-2011-3146, update the librsvg package to version 2.34.1 or later.
CVE-2011-3146 affects librsvg versions up to 2.34.0 and any software linked to it that processes crafted SVG files.
Yes, CVE-2011-3146 can potentially lead to remote code execution if an application linked to librsvg processes a malicious SVG file.
CVE-2011-3146 describes a NULL pointer dereference flaw in librsvg.