Out-of-bounds heap read in librsvg2 was found when parsing SVG file (CVE-2015-7557).
Stack exhaustion due to cyclic dependency causing to crash an application was found in librsvg2 while parsing SVG file (CVE-2015-7558).
The librsvg package has been updated to version 2.40.13, fixing these issues and several other bugs. See the upstream NEWS file for details.