librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.
References
Configurations
History
21 Nov 2024, 01:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://ftp.gnome.org/pub/GNOME/sources/librsvg/2.34/librsvg-2.34.1.news - | |
References | () http://git.gnome.org/browse/librsvg/commit/?id=34c95743ca692ea0e44778e41a7c0a129363de84 - Exploit, Patch | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065730.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065739.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066127.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2011-1289.html - | |
References | () http://secunia.com/advisories/45877 - Vendor Advisory | |
References | () https://bugs.launchpad.net/ubuntu/+source/librsvg/+bug/825497 - | |
References | () https://bugzilla.gnome.org/show_bug.cgi?id=658014 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=734936 - |
Information
Published : 2012-09-05 23:55
Updated : 2024-11-21 01:29
NVD link : CVE-2011-3146
Mitre link : CVE-2011-3146
CVE.ORG link : CVE-2011-3146
JSON object : View
Products Affected
gnome
- librsvg
CWE