CVE-2018-1000041
GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- gnome/librsvg · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/GNOME/librsvg/commit/c6ddf2ed4d768fd88adbea2b63f575cd523022eaThird Party Advisory
- https://github.com/ImageMagick/librsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547ddThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00013.htmlThird Party Advisory
- https://github.com/GNOME/librsvg/commit/c6ddf2ed4d768fd88adbea2b63f575cd523022eaThird Party Advisory
- https://github.com/ImageMagick/librsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547ddThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00013.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.