Resource exhaustion in libcroco - CVE-2020-12825
Published: May 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources caused by excessive recursion in cr_parser_parse_any_core in cr-parser.c. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
EMC ECS
Data Computing Appliance (DCA)
Gentoo Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
VMware Tanzu Application Service for VMs
Isolation Segment
libcroco3 (Ubuntu package)
libcroco-tools (Ubuntu package)
libcroco-0_6-3
libcroco-0_6-3-32bit
libcroco-debuginfo
libcroco-debugsource
libcroco-0_6-3-debuginfo-32bit
libcroco-0_6-3-debuginfo
libcroco-devel
libcroco
libcroco (Red Hat package)
libcroco-0_6-3-32bit-debuginfo
dev-libs/libcroco
sys-devel/gettext
gnome-base/gnome-shell
OpenShift Virtualization
VMware Tanzu Operations Manager
Dell EMC NetWorker vProxy
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-12825
libcroco-tools (Ubuntu package) - addressed in versions Ubuntu Pro, 0.6.13-1ubuntu0.1, 0.6.111ubuntu0.1~esm1
libcroco-0_6-3 - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-0_6-3-32bit - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-debuginfo - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-debugsource - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-0_6-3-debuginfo-32bit - update to 0.6.11-12.6.45
libcroco-0_6-3-debuginfo - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-devel - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco (Red Hat package) - addressed in versions 0.6.12-4.el8_2.1, 0.6.12-6.el7_9
libcroco-0_6-3-32bit-debuginfo - addressed in versions 0.6.12-150000.4.6.2, 0.6.13-3.3.1
dev-libs/libcroco - update to 0.6.13
sys-devel/gettext - update to 0.21
OpenShift Virtualization - update to 2.4.2
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
EMC ECS - update to 3.8.0.2
gnome-base/gnome-shell - update to 3.36.7
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC NetWorker vProxy - update to 4.3.0-36
Red Hat OpenShift Container Platform - update to 4.3.40
External References
Related Security Bulletins
- Denial of service in Gnome libcroco
- Red Hat Enterprise Linux 7 update for libcroco
- Ubuntu update for libcroco
- SUSE update for libcroco
- SUSE update for libcroco
- VMware Tanzu products update for Libcroco
- Gentoo update for Gnome Shell, gettext, libcroco
- SUSE update for libcroco
- SUSE update for libcroco
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell NetWorker vProxy
- Red Hat Enterprise Linux 8 update for libcroco
- Multiple vulnerabilities in Dell ECS
- Ubuntu update for libcroco
- Multiple vulnerabilities in OpenShift Virtualization 2.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3