Date: Mon, 21 Dec 2015 16:03:49 +0100 From: Adam Maris <amaris@...hat.com> To: oss-security@...ts.openwall.com Subject: CVE-2015-7557, CVE-2015-7558 librsvg2: Out-of-bounds heap read and stack exhaustion CVE-2015-7557: Out-of-bounds heap read in librsvg2 was found when parsing SVG file. Upstream patch: https://git.gnome.org/browse/librsvg/commit/rsvg-shapes.c?id=40af93e6eb1c94b90c3b9a0b87e0840e126bb8df CVE-2015-7558: Stack exhaustion due to cyclic dependency causing to crash an application was found in librsvg2 while parsing SVG file. It has been fixed in 2.40.12 by many commits that has rewritten the checks for cyclic references. RH bug: https://bugzilla.redhat.com/show_bug.cgi?id=1268243 -- Adam Maris / Red Hat Product Security
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.