PT-2017-4258 · Gnome+5 · Libcroco+5

Qflb.Wu

·

Published

2017-05-15

·

Updated

2024-08-13

·

CVE-2017-8834

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libcroco version 0.6.12
Description The issue is related to the cr tknzr parse comment function in the cr-tknzr.c component of the libcroco library, which can cause a denial of service due to a memory allocation error when processing a crafted CSS file. This can be exploited by remote attackers to cause a service disruption. The vulnerability is also associated with a buffer overflow in memory.
Recommendations For libcroco version 0.6.12, consider disabling the cr tknzr parse comment function as a temporary workaround until a patch is available. Restrict access to crafted CSS files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1596
BDU:2023-07606
CVE-2017-8834
MGASA-2019-0389
OPENSUSE-SU-2019_1575-1
OPENSUSE-SU-2020:0780-1
OPENSUSE-SU-2020_0780-1
OPENSUSE-SU-2024:10932-1
SUSE-SU-2019:1468-1
SUSE-SU-2019_1468-1
SUSE-SU-2020:1535-1
SUSE-SU-2020_1535-1
USN-5389-1
USN-6958-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Libcroco