Denial of Service Vulnerability in Libcroco Affecting Multiple Versions
CVE-2017-8834

6.5MEDIUM

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
12 June 2017

What is CVE-2017-8834?

The cr_tknzr_parse_comment function within cr-tknzr.c in Libcroco version 0.6.12 is susceptible to a vulnerability that permits the execution of remote denial of service attacks. By carefully crafting a CSS file, an attacker can trigger a memory allocation error, leading the application to crash or become unresponsive. This flaw underscores the importance of validating input files and recognizing potential threats in CSS processing.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-8834 : Denial of Service Vulnerability in Libcroco Affecting Multiple Versions