Candidate: CVE-2015-7558 PublicDate: 2016-05-20 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7558 Description: librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document. Ubuntu-Description: Notes: mdeslaur> intrusive backport Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=1268243 Priority: negligible Discovered-by: Gustavo Grieco Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_librsvg: upstream: https://git.gnome.org/browse/librsvg/commit/?id=a51919f7e1ca9c535390a746fbf6e28c8402dc61 upstream_librsvg: released (2.40.12) precise_librsvg: ignored (reached end-of-life) precise/esm_librsvg: DNE (precise was needed) trusty_librsvg: ignored (reached end-of-life) trusty/esm_librsvg: DNE (trusty was needed) vivid_librsvg: ignored (reached end-of-life) vivid/stable-phone-overlay_librsvg: ignored (reached end-of-life) vivid/ubuntu-core_librsvg: DNE wily_librsvg: ignored (reached end-of-life) xenial_librsvg: not-affected (2.40.13-1) esm-infra/xenial_librsvg: not-affected (2.40.13-1) yakkety_librsvg: not-affected (2.40.13-1) zesty_librsvg: not-affected (2.40.13-1) artful_librsvg: not-affected (2.40.13-1) bionic_librsvg: not-affected (2.40.13-1) cosmic_librsvg: not-affected (2.40.13-1) disco_librsvg: not-affected (2.40.13-1) devel_librsvg: not-affected (2.40.13-1)