Resource exhaustion in librsvg - CVE-2019-20446
Published: February 6, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect processing of nested patterns within SVG files in xml.rs in GNOME librsvg. A remote attacker can create a specially crafted SVG file, pass if to the affected application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
librsvg (Alpine package)
librsvg2-2 (Ubuntu package)
librsvg2 (Red Hat package)
chromium
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
How to mitigate CVE-2019-20446
librsvg (Alpine package) - update to 2.40.21-r0
librsvg2-2 (Ubuntu package) - addressed in versions 2.40.13-3ubuntu0.1, 2.40.13-3ubuntu0.2, 2.40.20-2ubuntu0.1, 2.40.20-2ubuntu0.2
librsvg2 (Red Hat package) - update to 2.42.7-4.el8
chromium - addressed in versions 80.0.3987.132-1.el8, 80.0.3987.132-1.fc30, 80.0.3987.132-1.fc31, 80.0.3987.149-1.el8, 80.0.3987.149-1.fc30, 80.0.3987.162-1.el8, 80.0.3987.163-1.el8, 81.0.4044.113-1.el8, 81.0.4044.113-2.el8, 81.0.4044.122-1.el8, 81.0.4044.138-1.el8
External References
Related Security Bulletins
- Denial of service in librsvg
- OpenSUSE Linux update for librsvg
- Resource exhaustion in librsvg (Alpine package)
- Red Hat Enterprise Linux 8 update for librsvg2
- Ubuntu update for librsvg
- Ubuntu update for librsvg
- Fedora EPEL 8 update for chromium
- Fedora 31 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium