SUSE: 2020:14323-1 moderate: librsvg
Summary
This update for librsvg fixes the following issues: - CVE-2019-20446: Fixed an issue where a crafted SVG file with nested patterns can cause denial of service (bsc#1162501). NOTE: Librsvg now has limits on the number of loaded XML elements, and the number of referenced elements within an SVG document. - CVE-2015-7558: librsvg allowed context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document (bsc#977985). - CVE-2016-6163: svg pattern linking to non-pattern fallback leads to invalid memory access, allowing to cause DoS (bsc#987877). - CVE-2018-1000041: Fixed leaking credentials via SVG files that reference UNC paths (bsc#1083232) - CVE-2016-4348: Fixed a denial of service parsing SVGs with circular definitions _rsvg_css_normalize_font_size() function (bsc#977986) - Fixed a stack exhaustion with circular references...
Read the Full AdvisoryReferences
#1083232 #1094213 #1162501 #977985 #977986
#987877
Cross- CVE-2015-7558 CVE-2016-4348 CVE-2016-6163
CVE-2018-1000041 CVE-2019-20446
Affected Products:
SUSE Linux Enterprise Debuginfo 11-SP4
https://www.suse.com/security/cve/CVE-2015-7558.html
https://www.suse.com/security/cve/CVE-2016-4348.html
https://www.suse.com/security/cve/CVE-2016-6163.html
https://www.suse.com/security/cve/CVE-2018-1000041.html
https://www.suse.com/security/cve/CVE-2019-20446.html
https://bugzilla.suse.com/1083232
https://bugzilla.suse.com/1094213
https://bugzilla.suse.com/1162501
https://bugzilla.suse.com/977985
https://bugzilla.suse.com/977986
https://bugzilla.suse.com/987877