Bug 734936 (CVE-2011-3146) - CVE-2011-3146 librsvg: object type mismatch leading to invalid pointer dereference
Summary: CVE-2011-3146 librsvg: object type mismatch leading to invalid pointer derefe...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-3146
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 735266 735267 736237
Blocks: 734942
TreeView+ depends on / blocked
 
Reported: 2011-08-31 22:01 UTC by Vincent Danen
Modified: 2023-05-12 22:39 UTC (History)
2 users (show)

Fixed In Version: librsvg 2.34.1
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-09-13 19:26:27 UTC
Embargoed:


Attachments (Terms of Use)
patch (43.86 KB, patch)
2011-09-02 04:28 UTC, Huzaifa S. Sidhpurwala
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1289 0 normal SHIPPED_LIVE Moderate: librsvg2 security update 2011-09-13 19:18:57 UTC

Description Vincent Danen 2011-08-31 22:01:20 UTC
A NULL pointer dereference flaw was reported [1] by Sauli Pahlman in librsvg.  If a program linked to librsvg where to open a crafted SVG file, it could cause that application to crash or potentially execute arbitrary code.

[1] https://launchpad.net/bugs/825497
https://bugzilla.gnome.org/show_bug.cgi?id=658014

Comment 3 Huzaifa S. Sidhpurwala 2011-09-02 04:28:16 UTC
Created attachment 521134 [details]
patch

Comment 5 Vincent Danen 2011-09-07 05:09:47 UTC
This is now public, and fixed in upstream 2.34.1:

http://git.gnome.org/browse/librsvg/commit/?id=34c95743ca692ea0e44778e41a7c0a129363de84

Comment 6 Huzaifa S. Sidhpurwala 2011-09-07 06:25:13 UTC
This issue does not affect the version of librsvg2 shipped with Red Hat
Enterprise Linux 4 and 5.

This issue affects the version of librsvg2 shipped with Red Hat Enterprise Linux 6.

This issue affects the version of librsvg2 shipped with Fedora 14 and Fedora 15.

Comment 7 Huzaifa S. Sidhpurwala 2011-09-07 06:26:35 UTC
Created librsvg2 tracking bugs for this issue

Affects: fedora-all [bug 736237]

Comment 8 Murray McAllister 2011-09-08 13:08:19 UTC
Acknowledgements:

Red Hat would like to thank the Ubuntu Security Team for reporting this issue. The Ubuntu Security Team acknowledges Sauli Pahlman as the original reporter.

Comment 9 errata-xmlrpc 2011-09-13 19:19:02 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:1289 https://rhn.redhat.com/errata/RHSA-2011-1289.html


Note You need to log in before you can comment on or make changes to this bug.