Infinite loop in librsvg - CVE-2015-7558
Published: January 31, 2020
Vulnerability identifier: #VU24812
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7558
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing cyclic references in an SVG document. A remote attacker can use a specially crafted SVG file to consume all available system resources and cause denial of service conditions.
Affected software
librsvg
librsvg (Debian package)
librsvg (Alpine package)
IBM Tivoli Storage Manager
librsvg (Debian package)
librsvg (Alpine package)
IBM Tivoli Storage Manager
How to mitigate CVE-2015-7558
Install updates from vendor's website.
librsvg - update to 2.40.12
librsvg (Debian package) - addressed in versions 2.40.5-1+deb8u2, 2.40.12-1
librsvg (Alpine package) - update to 2.40.12-r0
librsvg (Debian package) - addressed in versions 2.40.5-1+deb8u2, 2.40.12-1
librsvg (Alpine package) - update to 2.40.12-r0