A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsvg | Jul 23, 2020 | Jul 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade librsvg2-develUpgrade librsvg2-toolsUpgrade librsvg2 | Feb 3, 2021 | Jul 19, 2017 |
| Oracle Solaris | — | Upgrade image/library/librsvg to version 2.40.16-0.175.3.29.0.5.0 on Solaris 11.3 | Feb 22, 2018 | Jul 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 19, 2017 |
| Suse | — | Upgrade rsvg-viewUpgrade rsvg-thumbnailerUpgrade typelib-1_0-Rsvg-2_0Upgrade gdk-pixbuf-loader-rsvgUpgrade librsvg-2-2-32bitUpgrade librsvg-2-2Upgrade librsvg-devel | Aug 10, 2017 | Jul 19, 2017 |
| Ubuntu | — | Upgrade librsvg2-2 | Aug 5, 2020 | Jul 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub