Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 28 FEDORA-2019-d7ef743ef0 high: librsvg2 DoS issue

fedora
Calendar Grey March 26, 2019
Dist Fedora Esm H88
Mitigate possible denial-of-service vulnerabilities in librsvg2 by applying the security updates from Fedora 28 released on 2019-03-27, enhancing system reliability and performance
librsvg 2.42.7 release

Summary

An SVG library based on cairo.

librsvg 2.42.7 release. - Fix a denial-of-service condition from exponential

explosion of rendered elements, through nested use of SVG "use" elements in

malicious SVGs. This is similar to the XML "billion laughs attack" but for SVG

instancing.

* Mon Feb 18 2019 Kalev Lember - 2.42.7-2

- Rebuild

* Tue Sep 4 2018 Kalev Lember - 2.42.7-1

- Update to 2.42.7

* Wed Aug 8 2018 Kalev Lember - 2.42.6-1

- Update to 2.42.6

- Use bundled rust deps

su -c 'dnf upgrade --advisory FEDORA-2019-d7ef743ef0' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 28
Version: 2.42.7
Release: 2.fc28
Summary: An SVG library based on cairo

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here