Oval Definition:oval:com.redhat.rhsa:def:20111289
Revision Date:2011-09-13Version:639
Title:RHSA-2011:1289: librsvg2 security update (Moderate)
Description:The librsvg2 packages provide an SVG (Scalable Vector Graphics) library based on libart.

  • A flaw was found in the way librsvg2 parsed certain SVG files. An attacker could create a specially-crafted SVG file that, when opened, would cause applications that use librsvg2 (such as Eye of GNOME) to crash or, potentially, execute arbitrary code. (CVE-2011-3146)

    Red Hat would like to thank the Ubuntu Security Team for reporting this issue. The Ubuntu Security Team acknowledges Sauli Pahlman as the original reporter.

    All librsvg2 users should upgrade to these updated packages, which contain a backported patch to correct this issue. All running applications that use librsvg2 must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-3146
    CVE-2011-3146
    RHSA-2011:1289
    RHSA-2011:1289-01
    RHSA-2011:1289-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • librsvg2 is earlier than 0:2.26.0-5.el6_1.1
  • AND librsvg2 is signed with Red Hat redhatrelease2 key
  • librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1
  • AND librsvg2-devel is signed with Red Hat redhatrelease2 key
  • BACK