Lucene search

K
osvGoogleOSV:USN-5389-1
HistoryApr 26, 2022 - 2:05 p.m.

libcroco vulnerabilities

2022-04-2614:05:43
Google
osv.dev
19
libcroco
vulnerabilities
heap buffer overflow
denial of service
invalid utf-8
recursion
cve-2017-7960
cve-2017-8834
cve-2017-8871
cve-2020-12825
software

AI Score

7.3

Confidence

High

EPSS

0.005

Percentile

76.6%

It was discovered that Libcroco was incorrectly accessing data structures when
reading bytes from memory, which could cause a heap buffer overflow. An attacker
could possibly use this issue to cause a denial of service. (CVE-2017-7960)

It was discovered that Libcroco was incorrectly handling invalid UTF-8 values
when processing CSS files. An attacker could possibly use this issue to cause
a denial of service. (CVE-2017-8834, CVE-2017-8871)

It was discovered that Libcroco was incorrectly implementing recursion in one
of its parsing functions, which could cause an infinite recursion loop and a
stack overflow due to stack consumption. An attacker could possibly use this
issue to cause a denial of service. (CVE-2020-12825)