Segmentation Violation in LunaSVG v3.0.0 by KeepingGG
CVE-2024-57720

6.5MEDIUM

Key Information:

Vendor
KeepingGG
Status
LunaSVG
Vendor
CVE Published:
23 January 2025

Summary

The LunaSVG version 3.0.0 has been identified with a segmentation violation stemming from the plutovg_blend component, which can cause application instability and may result in unexpected behavior. Users are advised to review their deployments and consider upgrading to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.