7.1
CVSSv3

CVE-2020-12825

Published: 12/05/2020 Updated: 27/10/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

libcroco up to and including 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome libcroco

Vendor Advisories

Debian Bug report logs - #960527 libcroco: CVE-2020-12825 Package: src:libcroco; Maintainer for src:libcroco is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 13 May 2020 15:24:01 UTC Severity: important Tags: security, upstre ...
Several security issues were fixed in Libcroco ...
Synopsis Moderate: libcroco security update Type/Severity Security Advisory: Moderate Topic An update for libcroco is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Low: OpenShift Virtualization 242 Images Type/Severity Security Advisory: Low Topic Red Hat OpenShift Virtualization release 242 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security im ...
Synopsis Moderate: libcroco security update Type/Severity Security Advisory: Moderate Topic An update for libcroco is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Low: OpenShift Container Platform 4340 security and bug fix update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat OpenShift Container Platform 43Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring S ...
A stack overflow flaw was found in libcroco A service using libcroco's CSS parser could be crashed by a local, authenticated attacker, or an attacker utilizing social engineering, using a crafted input The highest threat from this vulnerability is to system availability (CVE-2020-12825) ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: [FD] libcroco multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Alan Coopersmith & ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: [FD] libcroco multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Alan Coopersmith & ...