First published: Fri May 20 2016(Updated: )
The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Librsvg2 | <=2.40.1 | |
Debian Linux | =8.0 | |
SUSE Linux | =42.1 | |
openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4348 has a severity level that can lead to denial of service due to application crashes.
To fix CVE-2016-4348, you should update librsvg to version 2.40.2 or later.
CVE-2016-4348 affects librsvg versions up to 2.40.1 and certain Debian and openSUSE systems.
CVE-2016-4348 allows context-dependent attackers to cause stack consumption via circular definitions in SVG documents.
Currently, the best workaround for CVE-2016-4348 is to avoid using SVG documents with circular definitions.