librsvg: Improper input validation vulnerability in rsvg-io.c
Published Feb 9, 2018
8.8
HIGHCVSS 3.0
EPSS 2.20%
Description
GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.
Affected products
No data.
Configuration 2
- 7.0
No data.
Red Hat Enterprise Linux 5
librsvg2
Not affected
Red Hat Enterprise Linux 6
librsvg2
Not affected
Red Hat Enterprise Linux 7
librsvg2
Not affected
Red Hat Enterprise Linux 8
librsvg2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | librsvg2 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | librsvg2 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | librsvg2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | librsvg2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The described vulnerability only affects librsvg on Windows, where UNC path references can lead to the NTLM hash being leaked.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.20% (0.02197) | 81.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.27% (0.02274) | 80.75th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.57% (0.00567) | 78.01th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.57% (0.00567) | 77.12th | v3 (v2023.03.01) |
| Aug 12, 2023 | 0.57% (0.00567) | 74.94th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.80% (0.00802) | 79.35th | v3 (v2023.03.01) |
| Jul 3, 2023 | 1.34% (0.01336) | 84.19th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.18% (0.01178) | 82.82th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.14% (0.01136) | 58.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.14% (0.01136) | 56.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.14% (0.01136) | 34.23th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.05% (0.01046) | 28.66th | v1 |
| Jan 6, 2022 | 1.05% (0.01046) | 28.03th | v1 |
| Sep 1, 2021 | 1.05% (0.01046) | 65.02th | v1 |
| Apr 14, 2021 | 1.05% (0.01046) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-1000041 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1588840 Issue Tracking
- https://github.com/GNOME/librsvg/commit/c6ddf2ed4d768fd88adbea2b63f575cd523022ea x_refsource_CONFIRMThird Party Advisory
- https://github.com/ImageMagick/librsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547dd x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00013.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000041
- https://www.cve.org/CVERecord?id=CVE-2018-1000041
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1000041 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1588840 | Issue Tracking | |
| https://github.com/GNOME/librsvg/commit/c6ddf2ed4d768fd88adbea2b63f575cd523022ea | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/ImageMagick/librsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547dd | x_refsource_CONFIRMThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/02/msg00013.html | mailing-listx_refsource_MLISTThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000041 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000041 |
Change history (0)
No recorded changes yet.