Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Scientific Linux: CVE-2011-3146 Moderate Security Update for librsvg2

Scientific Large Esm H500
Moderate: librsvg2 security update
Date: Tue, 13 Sep 2011 15:35:35 -0500
Reply-To: Pat Riehecky 
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Organization: Fermilab
Subject: Security ERRATA Moderate: librsvg2 on SL6.x i386/x86_64
MIME-Version: 1.0

Synopsis: Moderate: librsvg2 security update
Issue Date: 2011-09-13
CVE Numbers: CVE-2011-3146

The librsvg2 packages provide an SVG (Scalable Vector Graphics) library
based on libart.

A flaw was found in the way librsvg2 parsed certain SVG files. An attacker
could create a specially-crafted SVG file that, when opened, would cause
applications that use librsvg2 (such as Eye of GNOME) to crash or,
potentially, execute arbitrary code.
All librsvg2 users should upgrade to these updated packages, which contain
a backported patch to correct this issue. All running applications that use
librsvg2 must be restarted for this update to take effect.

SL6:
 i386
 librsvg2-2.26.0-5.el6_1.1.i686.rpm
 librsvg2-devel-2.26.0-5.el6_1.1.i686.rpm
 x86_64
 librsvg2-2.26.0-5.el6_1.1.i686.rpm
 librsvg2-2.26.0-5.el6_1.1.x86_64.rpm
 librsvg2-devel-2.26.0-5.el6_1.1.i686.rpm
 librsvg2-devel-2.26.0-5.el6_1.1.x86_64.rpm

- Scientific Linux Development Team
Your message here