Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2020:14323-1 Moderate: librsvg Denial of Service Fix

suse
Calendar Grey March 17, 2020
Dist Suse Esm H88
SUSE Security Patch for libgtk updates resolves several vulnerabilities. Ratings are moderate. Refer to the advisory for information on the implemented corrections.
An update that solves 5 vulnerabilities and has one errata is now available

Summary

This update for librsvg fixes the following issues: - CVE-2019-20446: Fixed an issue where a crafted SVG file with nested patterns can cause denial of service (bsc#1162501). NOTE: Librsvg now has limits on the number of loaded XML elements, and the number of referenced elements within an SVG document. - CVE-2015-7558: librsvg allowed context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document (bsc#977985). - CVE-2016-6163: svg pattern linking to non-pattern fallback leads to invalid memory access, allowing to cause DoS (bsc#987877). - CVE-2018-1000041: Fixed leaking credentials via SVG files that reference UNC paths (bsc#1083232) - CVE-2016-4348: Fixed a denial of service parsing SVGs with circular

References

#1083232 #1094213 #1162501 #977985 #977986

#987877

Cross- CVE-2015-7558 CVE-2016-4348 CVE-2016-6163

CVE-2018-1000041 CVE-2019-20446

Affected Products:

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-7558.html

https://www.suse.com/security/cve/CVE-2016-4348.html

https://www.suse.com/security/cve/CVE-2016-6163.html

https://www.suse.com/security/cve/CVE-2018-1000041.html

https://www.suse.com/security/cve/CVE-2019-20446.html

https://bugzilla.suse.com/1083232

https://bugzilla.suse.com/1094213

https://bugzilla.suse.com/1162501

https://bugzilla.suse.com/977985

https://bugzilla.suse.com/977986

https://bugzilla.suse.com/987877

Announcement ID: SUSE-SU-2020:14323-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here