MGASA-2016-0021
Dashboard / Vulnerabilities / MGASA-2016-0021
Summary: Updated librsvg packages fix security vulnerability
Details: Out-of-bounds heap read in librsvg2 was found when parsing SVG file (CVE-2015-7557). Stack exhaustion due to cyclic dependency causing to crash an application was found in librsvg2 while parsing SVG file (CVE-2015-7558). The librsvg package has been updated to version 2.40.13, fixing these issues and several other bugs. See the upstream NEWS file for details.
References: https://advisories.mageia.org/MGASA-2016-0021.html, https://bugs.mageia.org/show_bug.cgi?id=17378, https://git.gnome.org/browse/librsvg/tree/NEWS?id=a12e7b90e7b9fa6a6a325f39fb409722b06a6735, http://openwall.com/lists/oss-security/2015/12/21/5
Affected packages
Package
Name: librsvg
Purl: pkg:rpm/mageia/librsvg?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
