PT-2017-4259 · Gnome+5 · Libcroco+5

Qflb.Wu

·

Published

2017-05-15

·

Updated

2024-08-13

·

CVE-2017-8871

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libcroco version 0.6.12
Description The issue is related to the cr parser parse selector core function in cr-parser.c, which can lead to a denial of service due to an infinite loop and CPU consumption when processing a crafted CSS file. This can be exploited by remote attackers to cause service disruption.
Recommendations For libcroco version 0.6.12, consider disabling the cr parser parse selector core function as a temporary workaround until a patch is available. Restrict access to crafted CSS files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1596
AZL-44802
BDU:2023-07607
CVE-2017-8871
MGASA-2019-0389
OPENSUSE-SU-2019_1575-1
OPENSUSE-SU-2020:0780-1
OPENSUSE-SU-2020_0780-1
OPENSUSE-SU-2024:10932-1
SUSE-SU-2019:1468-1
SUSE-SU-2019_1468-1
SUSE-SU-2020:1535-1
SUSE-SU-2020_1535-1
USN-5389-1
USN-6958-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Libcroco