CVE-2017-7960: Medium severity Gnome Libcroco vulnerability
Last updated 13 August 2024
Other sources
The crinputnewfromuri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libcrocoto a version that resolves this vulnerability.Fixed in 0.6.12 - Compensating control
Mitigate the libcroco cr_input_new_from_uri heap-based buffer over-read denial-of-service by blocking or sandboxing processing of untrusted, attacker-controlled CSS files until the vulnerable libcroco version is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7960?
CVE-2017-7960 is classified as a denial of service vulnerability.
How do I fix CVE-2017-7960?
To fix CVE-2017-7960, upgrade libcroco to version 0.6.13 or later.
What versions of libcroco are affected by CVE-2017-7960?
CVE-2017-7960 affects libcroco versions 0.6.11 and 0.6.12.
What type of attack does CVE-2017-7960 involve?
CVE-2017-7960 involves a remote attacker causing a heap-based buffer over-read.
Can CVE-2017-7960 be exploited remotely?
Yes, CVE-2017-7960 can be exploited remotely through a crafted CSS file.