CVE-2016-6163Out-of-bounds Read in Librsvg

CWE-125Out-of-bounds Read8 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 57.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 3
Latest updateMay 17

Description

The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/librsvg< librsvg 2.40.9-2 (bookworm)
Debiangnome/librsvg< 2.40.9-2+3
NVDgnome/librsvg2.40.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j5fp-32j6-2xmr: The rsvg_pattern_fix_fallback function in rsvg-paint_server2022-05-17
OSV
CVE-2016-6163: The rsvg_pattern_fix_fallback function in rsvg-paint_server2017-02-03

📋Vendor Advisories

2
Red Hat
librsvg2: Out-of-bounds read when processing crafted SVG file2016-07-04
Debian
CVE-2016-6163: librsvg - The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2...2016

💬Community

3
Bugzilla
CVE-2016-6163 librsvg2: Out-of-bounds read when processing crafted SVG file2016-07-07
Bugzilla
CVE-2016-6163 mingw-librsvg2: librsvg2: Out-of-bounds read when processing crafted SVG file [fedora-all]2016-07-07
Bugzilla
CVE-2016-6163 librsvg2: Out-of-bounds read when processing crafted SVG file [fedora-all]2016-07-07
CVE-2016-6163 — Out-of-bounds Read in Debian Librsvg | cvebase