CVE-2017-7960 PUBLISHED

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

EPSS 0.53% · 67.2th percentile

Risk Scores

EPSS Score
0.53%
67.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibcroco0.6.11-1, 0.6.8-3, 0.6.9-1
Ubuntu:Pro:14.04:LTSlibcroco0.6.8-2, 0.6.8-2ubuntu1, 0

Timeline

References

Open in Interactive Console →