CVE-2018-1000041 describes an improper input validation vulnerability in GNOME librsvg, affecting versions before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea, including Debian Linux and GNOME librsvg. This high-severity vulnerability (CVSS 8.8) allows remote attackers to leak a victim's Windows username and NTLM password hash via SMB if the victim processes a specially crafted SVG file containing a UNC path. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.41.2CPE matchmatch criteria | cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.