header-logo
Suggest Exploit
vendor:
N/A
by:
NoiseBridge.net
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008

Malicious SVG file DoS

A malicious SVG file can cause a denial of service in Firefox's 'browse for file, preview' object, evince, and eog on Linux. It is unknown at this time whether code execution is possible.

Mitigation:

Ensure that SVG files are validated before being opened.
Source

Exploit-DB raw data:

"""
Malicious SVG file DoS

The following applications were tested in their latest revisions:
Firefox's "browse for file, preview" object on linux: affected
evince on linux: affected
eog on linux: affected
gimp on linux: affected
inkscape on linux: unaffected
Microsoft Visio on windows: unaffected

It is unknown at this time whether code execution is possible...
"""

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/6029.zip (2008-www.NoiseBridge.net.zip)

# milw0rm.com [2008-07-08]