First published: Wed Jul 19 2017(Updated: )
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME librsvg | =2.40.17 | |
debian/librsvg | 2.50.3+dfsg-1+deb11u1 2.54.7+dfsg-1~deb12u1 2.58.0+dfsg-1 2.59.0+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11464 is a vulnerability in GNOME librsvg 2.40.17 that raises a SIGFPE (Floating Point Exception) during SVG file parsing due to incorrect protection against division by zero.
The severity of CVE-2017-11464 is high, with a CVSS score of 7.8.
CVE-2017-11464 affects GNOME librsvg version 2.40.17, but it has been remediated in subsequent versions.
To fix CVE-2017-11464 in GNOME librsvg, update to version 2.44.10-2.1+deb10u3, 2.50.3+dfsg-1+deb11u1, 2.54.7+dfsg-1~deb12u1, or 2.54.7+dfsg-2.
You can find more information about CVE-2017-11464 at the following references: [1] [2] [3].