Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 21 Dec 2015 16:03:49 +0100
From: Adam Maris <amaris@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2015-7557, CVE-2015-7558 librsvg2: Out-of-bounds heap read and
 stack exhaustion

CVE-2015-7557: Out-of-bounds heap read in librsvg2 was found when 
parsing SVG file.

Upstream patch:

https://git.gnome.org/browse/librsvg/commit/rsvg-shapes.c?id=40af93e6eb1c94b90c3b9a0b87e0840e126bb8df

CVE-2015-7558: Stack exhaustion due to cyclic dependency causing to 
crash an application was found in librsvg2 while parsing SVG file. It 
has been fixed in 2.40.12 by many commits that has rewritten the checks 
for cyclic references.

RH bug:

https://bugzilla.redhat.com/show_bug.cgi?id=1268243

-- 
Adam Maris / Red Hat Product Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.