CVE-2017-11464

HIGH

GNOME librsvg <2.40.17 - Memory Corruption

Title source: llm

Description

A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.

Scores

CVSS v3 7.8
EPSS 0.0027
EPSS Percentile 49.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-369
Status draft

Affected Products (1)

gnome/librsvg

Timeline

Published Jul 19, 2017
Tracked Since Feb 18, 2026