Your submission was sent successfully! Close

CVE-2017-7960

Published: 19 April 2017

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

Priority

Low

CVSS 3 base score: 5.5

Status

Package Release Status
libcroco
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Needed

cosmic Ignored
(reached end-of-life)
disco Ignored
(reached end-of-life)
eoan Not vulnerable
(0.6.13-1)
focal Not vulnerable
(0.6.13-1)
groovy Not vulnerable
(0.6.13-1)
hirsute Does not exist

impish Does not exist

jammy Does not exist

precise Ignored
(end of ESM support, was needed)
trusty Needed

upstream
Released (0.6.11-3)
xenial
Released (0.6.11-1ubuntu0.1~esm1)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)