A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsvg | Jul 23, 2020 | Jul 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade librsvg2Upgrade librsvg2-develUpgrade librsvg2-tools | Feb 3, 2021 | Jul 19, 2017 |
| Oracle Solaris | — | Upgrade image/library/librsvg to version 2.40.16-0.175.3.29.0.5.0 on Solaris 11.3 | Feb 22, 2018 | Jul 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 19, 2017 |
| Suse | — | Upgrade librsvg-2-2-32bitUpgrade rsvg-thumbnailerUpgrade librsvg-2-2Upgrade librsvg-develUpgrade gdk-pixbuf-loader-rsvgUpgrade typelib-1_0-rsvg-2_0Upgrade rsvg-view | Aug 10, 2017 | Jul 19, 2017 |
| Ubuntu | — | Upgrade librsvg2-2 | Aug 5, 2020 | Jul 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub