6.5
CVSSv3

CVE-2017-8871

Published: 12/06/2017 Updated: 19/08/2020
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome libcroco 0.6.12

opensuse leap 42.3

Vendor Advisories

Several security issues were fixed in Libcroco ...
Debian Bug report logs - #864666 CVE-2017-8871 CVE-2017-8834 Package: src:libcroco; Maintainer for src:libcroco is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 12 Jun 2017 16:15:01 UTC Severity: important Tags: security, upstream ...

Exploits

libcroco multiple vulnerabilities ================ Author : qflbwu =============== Introduction: ============= Libcroco is a standalone css2 parsing and manipulation library The parser provides a low level event driven SAC like api and a css object model like api Libcroco provides a CSS2 selection engine and an experimental xml/css rendering e ...

Mailing Lists

Upstream closed these bugs as WONTFIX today since they have ended maintenance of the standalone libcroco, as discussed in the comments on gitlabgnomeorg/Archive/libcroco/-/issues/8 (which is a different security fix, for CVE-2020-12825) -Alan Coopersmith- alancoopersmith () oracle com Oracle Solaris Engin ...