Vulnerability Description
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Librsvg | < 2.40.21 |
| Opensuse | Leap | 15.1 |
| Fedoraproject | Fedora | 30 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Netapp | Active Iq Unified Manager | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.htmlMailing ListThird Party Advisory
- https://gitlab.gnome.org/GNOME/librsvg/issues/515Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20221111-0004/Third Party Advisory
- https://usn.ubuntu.com/4436-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.htmlMailing ListThird Party Advisory
- https://gitlab.gnome.org/GNOME/librsvg/issues/515Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00016.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20221111-0004/Third Party Advisory
- https://usn.ubuntu.com/4436-1/Third Party Advisory
FAQ
What is CVE-2019-20446?
CVE-2019-20446 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so tha...
How severe is CVE-2019-20446?
CVE-2019-20446 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20446?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Librsvg, Opensuse Leap, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux.