Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 21 Dec 2015 16:03:49 +0100
From: Adam Maris <amaris@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2015-7557, CVE-2015-7558 librsvg2: Out-of-bounds heap read and
 stack exhaustion

CVE-2015-7557: Out-of-bounds heap read in librsvg2 was found when 
parsing SVG file.

Upstream patch:

https://git.gnome.org/browse/librsvg/commit/rsvg-shapes.c?id=40af93e6eb1c94b90c3b9a0b87e0840e126bb8df

CVE-2015-7558: Stack exhaustion due to cyclic dependency causing to 
crash an application was found in librsvg2 while parsing SVG file. It 
has been fixed in 2.40.12 by many commits that has rewritten the checks 
for cyclic references.

RH bug:

https://bugzilla.redhat.com/show_bug.cgi?id=1268243

-- 
Adam Maris / Red Hat Product Security

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ