CVE-2018-17334: LIBSVG2 Project LIBSVG2
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because a strncpy copy limit is miscalculated.
Affected products
- LIBSVG2 Project LIBSVG2: up to and including 2012-10-19
Published 2018-09-22. Last modified 2026-06-17.