Vulnerability Description
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Librsvg | 2.40.17 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99956
- https://bugzilla.gnome.org/show_bug.cgi?id=783835Permissions Required
- https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef223Issue TrackingPatchThird Party Advisory
- https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972aIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.html
- https://usn.ubuntu.com/4436-1/
- http://www.securityfocus.com/bid/99956
- https://bugzilla.gnome.org/show_bug.cgi?id=783835Permissions Required
- https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef223Issue TrackingPatchThird Party Advisory
- https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972aIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.html
- https://usn.ubuntu.com/4436-1/
FAQ
What is CVE-2017-11464?
CVE-2017-11464 is a vulnerability with a CVSS score of 7.8 (HIGH). A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
How severe is CVE-2017-11464?
CVE-2017-11464 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11464?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Librsvg.