Bugzilla – Bug 977986
VUL-1: CVE-2016-4348: librsvg2: DoS parsing SVGs with circular definitions _rsvg_css_normalize_font_size() function
Last modified: 2020-05-12 17:51:32 UTC
rh#1331725 CVE-2016-4348 References: https://bugzilla.redhat.com/show_bug.cgi?id=1331725 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4348 http://seclists.org/oss-sec/2016/q2/164 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4348.html https://git.gnome.org/browse/librsvg/commit/?id=8ee18b22ece0f869cb4e2e021c01138cbb8a0226
This is an autogenerated message for OBS integration: This bug (977986) was mentioned in https://build.opensuse.org/request/show/393280 13.2+42.1 / librsvg
openSUSE-SU-2016:1333-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 977986 CVE References: CVE-2016-4348 Sources used: openSUSE Leap 42.1 (src): librsvg-2.40.15-7.1 openSUSE 13.2 (src): librsvg-2.40.15-10.1
federico, can you check if we need this in the sle versions too?
We already have those fixes in SLE; they came in with bug #977985.
This CVE is a duplicate of CVE-2015-7558 (bsc#977985). Fixed in all distros.