CVE-2011-3146
librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.
- Gnome Librsvg
- ≤ 2.34.0
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 4.4% (90th percentile)
- NVD status
- Modified
- Published
- 2012-09-05
CVE-2011-3146 at NVD
1 known exploit for CVE-2011-3146
Proof-of-concept code and exploit modules indexed by Sploitus