Back

HIGH

librsvg: Improper input validation vulnerability in rsvg-io.c

Published Feb 9, 2018

Description

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.

Affected products

Remediation

Red Hat statement

The described vulnerability only affects librsvg on Windows, where UNC path references can lead to the NTLM hash being leaked.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 9, 2018
Updated Aug 5, 2024
Reserved Feb 5, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 7, 2018