First published: Fri Oct 02 2015(Updated: )
A vulnerability causing stack exhaustion leading to DoS was found in librsvg2 when parsing SVG file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
rust/librsvg | <2.40.12 | 2.40.12 |
redhat/librsvg2 | <2.40.12 | 2.40.12 |
Debian Linux | =8.0 | |
CentOS Librsvg2 | <=2.40.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7558 has a severity level categorized as medium, as it can lead to denial of service due to stack exhaustion.
To fix CVE-2015-7558, update librsvg to version 2.40.12 or later.
CVE-2015-7558 affects librsvg versions prior to 2.40.12.
Yes, CVE-2015-7558 can be exploited by context-dependent attackers via crafted SVG files.
CVE-2015-7558 may cause applications using librsvg to enter an infinite loop, leading to a crash.