{"id":"CVE-2018-1000041","details":"GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.","modified":"2026-07-08T14:13:20.969704Z","published":"2018-02-09T23:29:01.260Z","related":["SUSE-SU-2018:1288-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"https://github.com/GNOME/librsvg/commit/c6ddf2ed4d768fd88adbea2b63f575cd523022ea"},{"type":"ADVISORY","url":"https://github.com/ImageMagick/librsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547dd"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/02/msg00013.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/librsvg","events":[{"introduced":"0"},{"fixed":"f822e90c7a91f12c76793ffe8e349584d4d813f8"},{"fixed":"c6ddf2ed4d768fd88adbea2b63f575cd523022ea"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.41.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.41.1","2.40.16","2.41.0","2.40.15","2.40.14","2.40.13","2.40.12","2.40.11","2.40.10","2.40.9","2.40.8","2.40.7","2.40.6","2.40.5","2.40.4","2.40.3","2.40.2","2.40.1","2.40.0","2.39.0","2.37.0","2.36.4","2.36.3","2.36.2","2.36.1","2.36.0","2.35.2","2.35.1","2.35.0","2.34.1","2.34.0","LIBRSVG_2_31_0","LIBRSVG_2_26_3","LIBRSVG_2_26_2","LIBRSVG_2_22_3","librsvg-2-13-93","librsvg-2-13-90","librsvg-2-13-3","help","GNOME_2_4_BRANCHPOINT","release-2-4-0","release-2-3-0","release-2-2-5","release-2-2-4","LIBRSVG_2_2_0","LIBRSVG_2_1_5","LIBRSVG_2_1_4","LIBRSVG_2_1_3","LIBRSVG_2_1_2","LIBRSVG_2_1_1","LIBRSVG_2_1_0","LIBRSVG_2_0_1","LIBRSVG_1_1_6","LIBRSVG_1_1_5","LIBRSVG_1_1_4","LIBRSVG_1_1_3","LIBRSVG_1_1_2","LIBRSVG_1_1_1","LIBRSVG_1_0_ANCHOR","LIBRSVG_1_0_1","LIBRSVG_1_0_0","LIBRSVG_0_0_1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000041.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/imagemagick/rsvg","events":[{"introduced":"0"},{"fixed":"f9d69eadd2b16b00d1a1f9f286122123f8e547dd"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000041.json","vanir_signatures_modified":"2026-07-08T14:13:20Z","vanir_signatures":[{"id":"CVE-2018-1000041-1102b600","signature_type":"Function","signature_version":"v1","source":"https://github.com/imagemagick/rsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547dd","target":{"file":"rsvg-io.c","function":"_rsvg_io_get_file_path"},"deprecated":false,"digest":{"length":459,"function_hash":"286195117430778398300004990827169289423"}},{"digest":{"line_hashes":["86022843286549888837123888105820422322","259425425816889724692286720210443290915","334295550670766026233948921873805680696","46920378987764707177351963029730365800"],"threshold":0.9},"id":"CVE-2018-1000041-b44f622c","signature_type":"Line","signature_version":"v1","source":"https://github.com/imagemagick/rsvg/commit/f9d69eadd2b16b00d1a1f9f286122123f8e547dd","target":{"file":"rsvg-io.c"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/librsvg","events":[{"introduced":"0"},{"fixed":"f822e90c7a91f12c76793ffe8e349584d4d813f8"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.41.2"}],"source":"CPE_RANGE"}}],"versions":["2.41.1","2.40.16","2.41.0","2.40.15","2.40.14","2.40.13","2.40.12","2.40.11","2.40.10","2.40.9","2.40.8","2.40.7","2.40.6","2.40.5","2.40.4","2.40.3","2.40.2","2.40.1","2.40.0","2.39.0","2.37.0","2.36.4","2.36.3","2.36.2","2.36.1","2.36.0","2.35.2","2.35.1","2.35.0","2.34.1","2.34.0","LIBRSVG_2_31_0","LIBRSVG_2_26_3","LIBRSVG_2_26_2","LIBRSVG_2_22_3","librsvg-2-13-93","librsvg-2-13-90","librsvg-2-13-3","help","GNOME_2_4_BRANCHPOINT","release-2-4-0","release-2-3-0","release-2-2-5","release-2-2-4","LIBRSVG_2_2_0","LIBRSVG_2_1_5","LIBRSVG_2_1_4","LIBRSVG_2_1_3","LIBRSVG_2_1_2","LIBRSVG_2_1_1","LIBRSVG_2_1_0","LIBRSVG_2_0_1","LIBRSVG_1_1_6","LIBRSVG_1_1_5","LIBRSVG_1_1_4","LIBRSVG_1_1_3","LIBRSVG_1_1_2","LIBRSVG_1_1_1","LIBRSVG_1_0_ANCHOR","LIBRSVG_1_0_1","LIBRSVG_1_0_0","LIBRSVG_0_0_1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000041.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}