A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsvg | Jul 23, 2020 | Jul 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade librsvg2-toolsUpgrade librsvg2-develUpgrade librsvg2 | Feb 3, 2021 | Jul 19, 2017 |
| Oracle Solaris | — | Upgrade image/library/librsvg to version 2.40.16-0.175.3.29.0.5.0 on Solaris 11.3 | Feb 22, 2018 | Jul 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 19, 2017 |
| Suse | — | Upgrade rsvg-viewUpgrade typelib-1_0-rsvg-2_0Upgrade librsvg-2-2-32bitUpgrade gdk-pixbuf-loader-rsvgUpgrade librsvg-develUpgrade rsvg-thumbnailerUpgrade librsvg-2-2 | Aug 10, 2017 | Jul 19, 2017 |
| Ubuntu | — | Upgrade librsvg2-2 | Aug 5, 2020 | Jul 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub