Mageia 2020-0159: librsvg security update
Summary
The updated packages fix a security vulnerability:
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested
patterns can cause denial of service when passed to the library for
processing. The attacker constructs pattern elements so that the number
of final rendered objects grows exponentially. (CVE-2019-20446)
References
- https://bugs.mageia.org/show_bug.cgi?id=26313
- http://lists.suse.com/pipermail/sle-security-updates/2020-March/006583.html
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20446
Resolution
MGASA-2020-0159 - Updated librsvg packages fix security vulnerability
SRPMS
- 7/core/librsvg-2.45.5-3.1.mga7