The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsvg | Mar 31, 2017 | Jan 19, 2016 |
| Freebsd | — | Upgrade librsvg2 | Dec 10, 2025 | Dec 22, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade librsvg2-develUpgrade librsvg2Upgrade librsvg2-tools | Dec 4, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade librsvg2-toolsUpgrade librsvg2-develUpgrade librsvg2 | Dec 18, 2019 | May 20, 2016 |
| Oracle Solaris | — | Upgrade image/library/librsvg to version 2.40.16-0.175.3.29.0.5.0 on Solaris 11.3 | Feb 22, 2018 | May 20, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub