CVE-2016-4348: Input Validation
Published May 20, 2016
·Updated
The rsvgcssnormalizefontsize function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
Affected Software
4 affected components
Gnome librsvg<=2.40.1
Debian Debian Linux=8.0
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Event History
May 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4348?
CVE-2016-4348 has a severity level that can lead to denial of service due to application crashes.
2
How do I fix CVE-2016-4348?
To fix CVE-2016-4348, you should update librsvg to version 2.40.2 or later.
3
What software is affected by CVE-2016-4348?
CVE-2016-4348 affects librsvg versions up to 2.40.1 and certain Debian and openSUSE systems.
4
What types of attacks does CVE-2016-4348 allow?
CVE-2016-4348 allows context-dependent attackers to cause stack consumption via circular definitions in SVG documents.
5
Is there a workaround for CVE-2016-4348?
Currently, the best workaround for CVE-2016-4348 is to avoid using SVG documents with circular definitions.