6.5

CVE-2019-20446

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnome ≫ Librsvg Version < 2.40.21
Gnome ≫ Librsvg Version >= 2.42.0 < 2.42.8
Gnome ≫ Librsvg Version >= 2.44.0 < 2.44.16
Opensuse ≫ Leap Version 15.1
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.13% 0.795
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://lists.debian.org/debian-lts-announce/2020/07/msg00016.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4436-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.html
Third Party Advisory
Mailing List
https://gitlab.gnome.org/GNOME/librsvg/issues/515
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
https://security.netapp.com/advisory/ntap-20221111-0004/
Third Party Advisory