Sploitus

CVE-2011-3146

1 known exploit for CVE-2011-3146

librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.

Affected products
Red Hat, Librsvg
Gnome Librsvg
≤ 2.34.0
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
4.4% (90th percentile)
NVD status
Modified
Published
2012-09-05
CVE-2011-3146 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-3146

Proof-of-concept code and exploit modules indexed by Sploitus