CVE-2017-7961: Buffer Overflow
DISPUTED The crtknzrparsergb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7961?
CVE-2017-7961 has a moderate severity rating due to its potential to cause denial of service by crashing applications.
How do I fix CVE-2017-7961?
To fix CVE-2017-7961, you should upgrade to a patched version of libcroco that is not affected by this vulnerability.
What types of attacks can CVE-2017-7961 lead to?
CVE-2017-7961 may allow remote attackers to cause a denial of service or potentially execute unspecified other attacks.
Which versions of libcroco are affected by CVE-2017-7961?
CVE-2017-7961 affects libcroco versions 0.6.11 and 0.6.12.
Is CVE-2017-7961 considered a critical vulnerability?
No, CVE-2017-7961 is not classified as a critical vulnerability but does pose a risk of application instability.