nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726 is affected by: Buffer Overflow
Published May 15, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.77%
Description
nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726 is affected by: Buffer Overflow. The impact is: Memory corruption leading to at least DoS. More severe impact vectors need more investigation. The component is: it's part of a svg processing library. function nsvg__parseColorRGB in src/nanosvg.h / line 1227. The attack vector is: It depends library usage. If input is passed from the network, then network connectivity is enough. Most likely an attack will require opening a specially crafted .svg file.
Affected products
-
- Version after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Nanosvg Library | Nanosvg | n/a |
|
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://0day.work/cve-2019-1000032-memory-corruption-in-nanosvg/ x_refsource_MISCExploitThird Party Advisory
- https://github.com/memononen/nanosvg/ x_refsource_MISCThird Party Advisory
- https://github.com/memononen/nanosvg/issues/136 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://0day.work/cve-2019-1000032-memory-corruption-in-nanosvg/ | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/memononen/nanosvg/ | x_refsource_MISCThird Party Advisory | |
| https://github.com/memononen/nanosvg/issues/136 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.