The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
2016-05-20T14:59:06.467
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnome | librsvg | ≤ 2.40.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | opensuse | leap | 42.1 | Yes |
Operating System | opensuse | opensuse | 13.2 | Yes |