Bug 1331724 (CVE-2016-4347) - CVE-2016-4347 Rejected: CVE-2016-4347
Summary: CVE-2016-4347 Rejected: CVE-2016-4347
Keywords:
Status: CLOSED DUPLICATE of bug 1268243
Alias: CVE-2016-4347
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1331727 1331728
Blocks: 1331729
TreeView+ depends on / blocked
 
Reported: 2016-04-29 11:49 UTC by Martin Prpič
Modified: 2021-02-17 03:57 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-06-03 13:04:17 UTC
Embargoed:


Attachments (Terms of Use)

Description Martin Prpič 2016-04-29 11:49:22 UTC
A denial of service flaw was found in the way the librsvg2 library parsed SVG files. A specially crafted SVG file with circular definitions could cause an application using librsvg2 to crash.

This flaw is in the rsvg_cairo_pop_discrete_layer(), rsvg_cairo_pop_render_stack(), and rsvg_cairo_generate_mask() functions.

Reference (including reproducer):

http://seclists.org/oss-sec/2016/q2/161

Comment 1 Martin Prpič 2016-04-29 11:59:32 UTC
Created librsvg2 tracking bugs for this issue:

Affects: fedora-all [bug 1331727]

Comment 2 Martin Prpič 2016-04-29 11:59:38 UTC
Created mingw-librsvg2 tracking bugs for this issue:

Affects: fedora-all [bug 1331728]

Comment 6 Andrej Nemec 2016-06-06 15:37:47 UTC
This CVE was rejected by Mitre.

Common Vulnerabilities and Exposures assigned an identifier CVE-2016-4347 to
the following vulnerability:

Name: CVE-2016-4347
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4347
Assigned: 20160428

** REJECT **
DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2015-7558.  Reason:
This candidate is a reservation duplicate of CVE-2015-7558.  Notes:
All CVE users should reference CVE-2015-7558 instead of this
candidate.  All references and descriptions in this candidate have
been removed to prevent accidental usage.

Comment 7 Doran Moppert 2020-02-10 04:31:47 UTC
Statement:

This flaw was found to be a duplicate of CVE-2015-7558. Please see https://access.redhat.com/security/cve/CVE-2015-7558 for information about affected products and security errata.


Note You need to log in before you can comment on or make changes to this bug.