Out-of-bounds read in librsvg - CVE-2016-6163
Published: February 1, 2020
librsvg
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the rsvg_pattern_fix_fallback() function in rsvg-paint_server.c in librsvg when processing SVG files. A remote attacker can use a specially crafted SVG file to trigger out-of-bounds read error and read contents of memory on the system.