Logo
componentlibrsvg
Name
librsvg
Version
2.57.1
Type
library
Description
Library for rendering SVG files
Licenses
LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:gnome:librsvg:2.57.1:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.52.10
master
2.62.2

Patches#


#
Title
Author
Resolve
1
Makefile.am: pass rust target to cargo also when not cross
Alexander Kanavin <alex@linutronix.de>
2
Don't build rsvg-loader in cross builds
Ross Burton <ross.burton@arm.com>

Vulnerabilities#


Name
Analysis
Description
False Positive
GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.