In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-02T00:00:00
Updated: 2024-08-05T02:39:09.924Z
Reserved: 2020-02-02T00:00:00
Link: CVE-2019-20446
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-02T14:15:10.523
Modified: 2024-11-21T04:38:30.303
Link: CVE-2019-20446
Redhat