CVE-2016-6163: Medium severity Gnome librsvg vulnerability
An out-of-bounds read vulnerability that leads to segmentation fault was found in librsvg2 when processing specially crafted SVG file using Firefox.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q3/7
Upstream patch:
https://git.gnome.org/browse/librsvg/commit/?id=0035e95118a60c0cd3949c2300472d805e16a022
Other sources
The rsvgpatternfixfallback function in rsvg-paintserver.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6163?
CVE-2016-6163 is classified as a high severity vulnerability due to its ability to cause a segmentation fault.
How do I fix CVE-2016-6163?
To fix CVE-2016-6163, update the librsvg2 package to version 2.40.7 or later.
What software is affected by CVE-2016-6163?
CVE-2016-6163 affects librsvg2 versions prior to 2.40.7.
What type of vulnerability is CVE-2016-6163?
CVE-2016-6163 is an out-of-bounds read vulnerability.
Can CVE-2016-6163 be exploited through the web?
Yes, CVE-2016-6163 can be exploited by processing specially crafted SVG files in applications like Firefox.