Unspecified vulnerability was found [1] in Skia (2D rendering engine used in Chromium) which leads to uninitialized memory read. [1]: https://code.google.com/p/chromium/issues/detail?id=391001 External References: http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
Upstream patch: https://skia.googlesource.com/skia/+/1c577cd3ee331944b9061ee0eec147b211ee563c
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2014:1894 https://rhn.redhat.com/errata/RHSA-2014-1894.html
Analysis: On further investigation, it was found that this issue does not affect librsvg2. It only affects the skia library. Statement: This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5, 6 and 7.