Vulnerability Name:

CVE-2016-6163 (CCN-125339)

Assigned:2016-07-05
Published:2017-02-03
Updated:2017-02-07
Summary:The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2016-6163

Source: CCN
Type: oss-sec Mailing List, Mon, 4 Jul 2016 21:13:05 +0200
Browsing and attaching images considered harmful in Linux

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20160704 Browsing and attaching images considered harmful in Linux

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20160705 Re: Browsing and attaching images considered harmful in Linux

Source: CCN
Type: Red Hat Bugzilla – Bug 1353520
(CVE-2016-6163) CVE-2016-6163 librsvg2: Out-of-bounds read when processing crafted SVG file

Source: CONFIRM
Type: Issue Tracking, Patch
https://bugzilla.redhat.com/show_bug.cgi?id=1353520

Source: XF
Type: UNKNOWN
librsvg2-cve20166163-dos(125339)

Source: CCN
Type: librsvg GIT Repository
bgo#744299 - Ensure the type of pattern fallbacks

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:librsvg:2.40.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20166163
    V
    CVE-2016-6163
    2023-02-11
    oval:org.opensuse.security:def:34052
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:30162
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:33737
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:34570
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:33987
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:33725
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:33726
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:34526
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:32981
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:33956
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:34501
    P
    Security update for fastjar (Low)
    2021-08-06
    oval:org.opensuse.security:def:34462
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:31196
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:30076
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:35248
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:31159
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32894
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:28945
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:34026
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:30019
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:34413
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:32837
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:28861
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:29300
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:28509
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:29151
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33349
    P
    Security update for openssh-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33820
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28520
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29200
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29715
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30315
    P
    Security update for tftp
    2020-12-01
    oval:org.opensuse.security:def:28588
    P
    Security update for Mozilla NSS
    2020-12-01
    oval:org.opensuse.security:def:29239
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29716
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:30370
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28719
    P
    Security update for kdebase4-workspace (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29256
    P
    Security update for tomcat6 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29727
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:30419
    P
    Security update for xorg-x11-libXp
    2020-12-01
    oval:org.opensuse.security:def:32518
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33137
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34109
    P
    Security update for mutt
    2020-12-01
    oval:org.opensuse.security:def:35208
    P
    Security update for libgcrypt
    2020-12-01
    oval:org.opensuse.security:def:28804
    P
    Security update for openvpn
    2020-12-01
    oval:org.opensuse.security:def:29800
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30458
    P
    Security update for Mesa
    2020-12-01
    oval:org.opensuse.security:def:32519
    P
    ghostscript-fonts-other on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33194
    P
    libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34198
    P
    Security update for pcsc-lite
    2020-12-01
    oval:org.opensuse.security:def:29938
    P
    Security update for libksba
    2020-12-01
    oval:org.opensuse.security:def:29932
    P
    Security update for libgnomesu
    2020-12-01
    oval:org.opensuse.security:def:30477
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:32530
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33243
    P
    python-lxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34355
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:29974
    P
    Security update for librsvg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30521
    P
    Security update for gtk2
    2020-12-01
    oval:org.opensuse.security:def:32608
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33282
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28508
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29097
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32743
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33305
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201661630000000
    V
    CVE-2016-6163 on Ubuntu 18.04 LTS (bionic) - low.
    2017-02-03
    oval:com.ubuntu.artful:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 17.10 (artful) - low.
    2017-02-03
    oval:com.ubuntu.trusty:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 14.04 LTS (trusty) - low.
    2017-02-03
    oval:com.ubuntu.xenial:def:201661630000000
    V
    CVE-2016-6163 on Ubuntu 16.04 LTS (xenial) - low.
    2017-02-03
    oval:com.ubuntu.bionic:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 18.04 LTS (bionic) - low.
    2017-02-03
    oval:com.ubuntu.xenial:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 16.04 LTS (xenial) - low.
    2017-02-03
    oval:com.ubuntu.cosmic:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 18.10 (cosmic) - low.
    2017-02-03
    oval:com.ubuntu.cosmic:def:201661630000000
    V
    CVE-2016-6163 on Ubuntu 18.10 (cosmic) - low.
    2017-02-03
    oval:com.ubuntu.precise:def:20166163000
    V
    CVE-2016-6163 on Ubuntu 12.04 LTS (precise) - low.
    2017-02-03
    BACK
    gnome librsvg 2.40.2