VulnerabilityModified
CVE-2019-20446
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing.
MEDIUM 6.5EPSS 2.13%
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- gnome/librsvg · opensuse/leap · fedoraproject/fedora · debian/debian linux · canonical/ubuntu linux · netapp/active iq unified manager
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.htmlMailing List, Third Party Advisory
- https://gitlab.gnome.org/GNOME/librsvg/issues/515Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
- https://security.netapp.com/advisory/ntap-20221111-0004/Third Party Advisory
- https://usn.ubuntu.com/4436-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.htmlMailing List, Third Party Advisory
- https://gitlab.gnome.org/GNOME/librsvg/issues/515Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
- https://security.netapp.com/advisory/ntap-20221111-0004/Third Party Advisory
- https://usn.ubuntu.com/4436-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.