Bug 1797608 (CVE-2019-20446) - CVE-2019-20446 librsvg: Resource exhaustion via crafted SVG file with nested patterns
Summary: CVE-2019-20446 librsvg: Resource exhaustion via crafted SVG file with nested ...
Keywords:
Status: NEW
Alias: CVE-2019-20446
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1797613 1797614 1804519 1797609 1797610 1797611 1804518
Blocks: 1797612
TreeView+ depends on / blocked
 
Reported: 2020-02-03 13:57 UTC by Pedro Sampaio
Modified: 2020-07-24 22:38 UTC (History)
22 users (show)

Fixed In Version: librsvg 2.46.2
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Pedro Sampaio 2020-02-03 13:57:02 UTC
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Upstream issue:

https://gitlab.gnome.org/GNOME/librsvg/issues/515

Comment 1 Pedro Sampaio 2020-02-03 13:57:54 UTC
Created chromium tracking bugs for this issue:

Affects: epel-all [bug 1797611]
Affects: fedora-all [bug 1797610]


Created firefox tracking bugs for this issue:

Affects: fedora-all [bug 1797613]


Created librsvg2 tracking bugs for this issue:

Affects: fedora-all [bug 1797609]


Created thunderbird tracking bugs for this issue:

Affects: fedora-all [bug 1797614]

Comment 2 Huzaifa S. Sidhpurwala 2020-02-18 10:37:23 UTC
Upstream commit: https://gitlab.gnome.org/GNOME/librsvg/commit/572f95f739529b865e2717664d6fefcef9493135

Comment 5 Huzaifa S. Sidhpurwala 2020-02-19 03:56:46 UTC
Statement:

This flaw is similar to billion laughs. A specially-crafted XML file can cause librsvg to consume excessive memory and result in denial of service. This flaw also affects browsers. Currently Mozilla and Google are working on updates for Firefox and Chromium browser respectively.

Comment 6 Huzaifa S. Sidhpurwala 2020-02-19 04:03:06 UTC
Mitigation:

This flaw is triggered when untrusted XML files are parsed with applications compiled with librsvg2 library. Applications which do not parse untrusted XML files are not affected by this flaw.


Note You need to log in before you can comment on or make changes to this bug.