User: Password:
|
|
Subscribe / Log in / New account

Scientific Linux alert SL-libr-20110913 (librsvg2)

From:  Pat Riehecky <riehecky@fnal.gov>
To:  "SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV" <SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV>
Subject:  Security ERRATA Moderate: librsvg2 on SL6.x i386/x86_64
Date:  Tue, 13 Sep 2011 15:35:35 -0500
Message-ID:  <4E6FBE97.5010509@fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: librsvg2 security update Issue Date: 2011-09-13 CVE Numbers: CVE-2011-3146 The librsvg2 packages provide an SVG (Scalable Vector Graphics) library based on libart. A flaw was found in the way librsvg2 parsed certain SVG files. An attacker could create a specially-crafted SVG file that, when opened, would cause applications that use librsvg2 (such as Eye of GNOME) to crash or, potentially, execute arbitrary code. All librsvg2 users should upgrade to these updated packages, which contain a backported patch to correct this issue. All running applications that use librsvg2 must be restarted for this update to take effect. SL6: i386 librsvg2-2.26.0-5.el6_1.1.i686.rpm librsvg2-devel-2.26.0-5.el6_1.1.i686.rpm x86_64 librsvg2-2.26.0-5.el6_1.1.i686.rpm librsvg2-2.26.0-5.el6_1.1.x86_64.rpm librsvg2-devel-2.26.0-5.el6_1.1.i686.rpm librsvg2-devel-2.26.0-5.el6_1.1.x86_64.rpm - Scientific Linux Development Team


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds