An out-of-bounds read vulnerability that leads to segmentation fault was found in librsvg2 when processing specially crafted SVG file using Firefox.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q3/7
Upstream patch:
https://git.gnome.org/browse/librsvg/commit/?id=0035e95118a60c0cd3949c2300472d805e16a022