Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-20446
Description:In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2020.0604.1   1.3.6.1.4.1.25623.1.1.10.2020.0159   1.3.6.1.4.1.25623.1.1.4.2020.0629.2   1.3.6.1.4.1.25623.1.1.4.2020.0629.1   1.3.6.1.4.1.25623.1.0.853071  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-20446
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
https://gitlab.gnome.org/GNOME/librsvg/issues/515
https://lists.debian.org/debian-lts-announce/2020/07/msg00016.html
SuSE Security Announcement: openSUSE-SU-2020:0343 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.html
https://usn.ubuntu.com/4436-1/




© 1998-2025 E-Soft Inc. All rights reserved.