CVE-2017-8871: High severity libcroco vulnerability
Last updated 13 August 2024
Other sources
The crparserparseselectorcore function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8871?
CVE-2017-8871 has a severity rating that typically indicates a denial of service risk, leading to infinite loops and high CPU consumption.
How do I fix CVE-2017-8871?
To fix CVE-2017-8871, update libcroco to a version later than 0.6.12 where the vulnerability has been addressed.
What software versions are affected by CVE-2017-8871?
CVE-2017-8871 affects libcroco version 0.6.12 and earlier versions on platforms such as Debian and openSUSE Leap 42.3.
What kind of attack does CVE-2017-8871 enable?
CVE-2017-8871 enables remote attackers to conduct a denial of service attack by exploiting crafted CSS files.
Where can I find more information about CVE-2017-8871?
More information about CVE-2017-8871 can typically be found in security advisories and vulnerability databases.