CVE-2015-7558: Input Validation
Published Oct 2, 2015
·Updated
A vulnerability causing stack exhaustion leading to DoS was found in librsvg2 when parsing SVG file.
Other sources
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.
Affected Software
4 affected componentsFixes available
rust/librsvg<2.40.12
2.40.12
redhat/librsvg2<2.40.12
2.40.12
Debian Debian Linux=8.0
Gnome librsvg<=2.40.11
Event History
Oct 2, 2015
Data Sourced
via Red Hat·09:25 AM
DescriptionSeverityAffected Software
May 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
03:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-7558?
CVE-2015-7558 has a severity level categorized as medium, as it can lead to denial of service due to stack exhaustion.
2
How do I fix CVE-2015-7558?
To fix CVE-2015-7558, update librsvg to version 2.40.12 or later.
3
Which versions of librsvg are affected by CVE-2015-7558?
CVE-2015-7558 affects librsvg versions prior to 2.40.12.
4
Can CVE-2015-7558 be exploited remotely?
Yes, CVE-2015-7558 can be exploited by context-dependent attackers via crafted SVG files.
5
What impact does CVE-2015-7558 have on applications?
CVE-2015-7558 may cause applications using librsvg to enter an infinite loop, leading to a crash.