CVE-2019-20446: Medium severity Gnome librsvg vulnerability
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-20446?
CVE-2019-20446 is a vulnerability in GNOME librsvg that allows a crafted SVG file with nested patterns to cause denial of service.
What is the severity of CVE-2019-20446?
The severity of CVE-2019-20446 is medium with a CVSS score of 6.5.
How does CVE-2019-20446 work?
CVE-2019-20446 works by constructing pattern elements in a crafted SVG file to cause exponential growth of rendered objects, leading to denial of service.
Which software versions of GNOME librsvg are affected by CVE-2019-20446?
Versions up to and including 2.46.2 of GNOME librsvg are affected by CVE-2019-20446.
How can I fix CVE-2019-20446?
To fix CVE-2019-20446, upgrade to version 2.46.4-1 or later of GNOME librsvg.