Bugzilla – Bug 714980
VUL-0: librsvg security issue
Last modified: 2017-01-11 02:01:16 UTC
Your friendly security team received the following report via vendor-sec. Please respond ASAP. This issue is not public yet, please keep any information about it inside SUSE. Note that build.opensuse.org *cannot* be used to prepare embargoed updates. Specially crafted SVG files could make librsvg dereference a function pointer which potentially allows to execute arbitrary code (CVE-2011-3146). https://launchpad.net/bugs/825497
CVE-2011-3146
https://bugzilla.gnome.org/show_bug.cgi?id=658014
The SWAMPID for this issue is 43002. This issue was rated as moderate. Please submit fixed packages until 2011-09-16. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
I have packages ready to test for openSUSE 11.3 and 11.4 (they both need testing). I need to fix virtualbox to test them (it's not installable on factory), though :/
bug is public meanwhile: https://bugzilla.gnome.org/show_bug.cgi?id=658014#c7
SLE-10-SP3/SP4 does not seem to be affected, whereas SLE-11-SP1 is.
I've been able to test on 11.3 and 11.4, and the issue is fixed. So I submitted the update for openSUSE: 82364 82365.
Update released for: gdk-pixbuf-loader-rsvg, gdk-pixbuf-loader-rsvg-debuginfo, gtk2-engine-svg, gtk2-engine-svg-debuginfo, librsvg, librsvg-2-2, librsvg-2-2-debuginfo, librsvg-debuginfo, librsvg-debugsource, librsvg-devel, rsvg-view, rsvg-view-debuginfo Products: openSUSE 11.3 (debug, i586, x86_64) openSUSE 11.4 (debug, i586, x86_64)
Update released for: librsvg, librsvg-32bit, librsvg-debuginfo, librsvg-debuginfo-32bit, librsvg-debuginfo-x86, librsvg-debugsource, librsvg-devel, librsvg-plugin, librsvg-x86, rsvg-view Products: SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLE-DESKTOP 11-SP1 (i386, x86_64) SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLE-SERVER 11-SP1-TERADATA (x86_64) SLES4VMWARE 11-SP1 (i386, x86_64)
This is an autogenerated message for OBS integration: This bug (714980) was mentioned in https://build.opensuse.org/request/show/86863 Evergreen:11.2 / librsvg
This is an autogenerated message for OBS integration: This bug (714980) was mentioned in https://build.opensuse.org/request/show/87186 Evergreen:11.1 / librsvg
This is an autogenerated message for OBS integration: This bug (714980) was mentioned in https://build.opensuse.org/request/show/87414 Evergreen:11.1 / librsvg