It was reported that out-of-band heap read is performed in librsvg2 when parsing SVG file.
Red Hat would like to thank Gustavo Grieco for reporting this issue.
I've downloaded the reproducer, and neither firefox 41 nor eog 3.18.0 crash. They both report errors trying to load the image.
Created librsvg2 tracking bugs for this issue:
Affects: fedora-all [bug 1293344]
Created mingw-librsvg2 tracking bugs for this issue:
Affects: fedora-all [bug 1293345]