Hide Forgot
It was reported that out-of-band heap read is performed in librsvg2 when parsing SVG file.
Acknowledgements: Red Hat would like to thank Gustavo Grieco for reporting this issue.
I've downloaded the reproducer, and neither firefox 41 nor eog 3.18.0 crash. They both report errors trying to load the image.
Upstream patch: https://git.gnome.org/browse/librsvg/commit/rsvg-shapes.c?id=40af93e6eb1c94b90c3b9a0b87e0840e126bb8df
Created librsvg2 tracking bugs for this issue: Affects: fedora-all [bug 1293344]
Created mingw-librsvg2 tracking bugs for this issue: Affects: fedora-all [bug 1293345]