GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsvg | Feb 19, 2019 | Feb 9, 2018 |
| Oracle Solaris | — | Upgrade desktop/xdg/xdg-utils to version 1.1.3-11.4.15.0.1.2.0 on Solaris 11.4Upgrade library/libsoup to version 2.57.1-11.4.15.0.1.2.0 on Solaris 11.4Upgrade library/liblouis to version 3.5.0-11.4.15.0.1.2.0 on Solaris 11.4Upgrade image/library/librsvg to version 2.40.16-11.4.15.0.1.2.0 on Solaris 11.4Upgrade desktop/pdf-viewer/evince to version 3.25.4-11.4.15.0.1.2.0 on Solaris 11.4 | Nov 20, 2019 | Feb 9, 2018 |
| Suse | — | Upgrade librsvg-2-2Upgrade rsvg-viewUpgrade gdk-pixbuf-loader-rsvgUpgrade librsvg-2-2-32bitUpgrade librsvg-develUpgrade typelib-1_0-Rsvg-2_0 | May 16, 2018 | Feb 9, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub