6.5
CVSSv3

CVE-2017-8834

Published: 12/06/2017 Updated: 19/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote malicious users to cause a denial of service (memory allocation error) via a crafted CSS file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome libcroco 0.6.12

opensuse leap 42.3

Vendor Advisories

Debian Bug report logs - #864666 CVE-2017-8871 CVE-2017-8834 Package: src:libcroco; Maintainer for src:libcroco is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 12 Jun 2017 16:15:01 UTC Severity: important Tags: security, upstream ...
Several security issues were fixed in Libcroco ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: [FD] libcroco multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Alan Coopersmith & ...