CVE-2018-17334: LIBSVG2 Project LIBSVG2

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because a strncpy copy limit is miscalculated.

Affected products

Published 2018-09-22. Last modified 2026-06-17.