CVE-2019-20446
Summary
| CVE | CVE-2019-20446 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-02 14:15:00 UTC |
| Updated | 2023-11-07 03:09:00 UTC |
| Description | In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 30 Update: chromium-80.0.3987.149-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| DoS vulnerability in librsvg (#515) · Issues · GNOME / librsvg · GitLab |
MISC |
gitlab.gnome.org |
Vendor Advisory |
| [SECURITY] Fedora 31 Update: chromium-80.0.3987.132-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2019-20446 GNOME Librsvg Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| USN-4436-1: librsvg vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: chromium-80.0.3987.132-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0343-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2285-1] librsvg security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 30 Update: chromium-80.0.3987.149-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377571 Alibaba Cloud Linux Security Update for librsvg2 (ALINUX3-SA-2022:0075)
- 501058 Alpine Linux Security Update for librsvg
- 940111 AlmaLinux Security Update for librsvg2 (ALSA-2020:4709)
- 960437 Rocky Linux Security Update for librsvg2 (RLSA-2020:4709)