Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP2-2020-629


Security update for librsvg


Type: security
Severity: moderate
Issued: 2020-07-07
Description:
This update for librsvg to version 2.42.8 fixes the following issues:

librsvg was updated to version 2.42.8 fixing the following issues:	  

- CVE-2019-20446: Fixed an issue where a crafted SVG file with nested
  patterns can cause denial of service (bsc#1162501).
  NOTE: Librsvg now has limits on the number of loaded XML elements,
  and the number of referenced elements within an SVG document. 
- Fixed a stack exhaustion with circular references in <use>
  elements.
- Fixed a denial-of-service condition from exponential explosion
  of rendered elements, through nested use of SVG "use" elements in
  malicious SVGs.  


              

Packages


  • librsvg-2.42.8-3.3.1