Infinite loop in librsvg - CVE-2015-7558

 

Infinite loop in librsvg - CVE-2015-7558

Published: January 31, 2020


Vulnerability identifier: #VU24812
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7558
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing cyclic references in an SVG document. A remote attacker can use a specially crafted SVG file to consume all available system resources and cause denial of service conditions.


Affected software

librsvg
librsvg (Debian package)
librsvg (Alpine package)
IBM Tivoli Storage Manager

How to mitigate CVE-2015-7558

Install updates from vendor's website.

librsvg - update to 2.40.12
librsvg (Debian package) - addressed in versions 2.40.5-1+deb8u2, 2.40.12-1
librsvg (Alpine package) - update to 2.40.12-r0

External References

Related Security Bulletins