Resource exhaustion in libcroco - CVE-2020-12825

 

Resource exhaustion in libcroco - CVE-2020-12825

Published: May 15, 2020


Vulnerability identifier: #VU27951
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12825
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources caused by excessive recursion in cr_parser_parse_any_core in cr-parser.c. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

libcroco
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
EMC ECS
Data Computing Appliance (DCA)
Gentoo Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
VMware Tanzu Application Service for VMs
Isolation Segment
libcroco3 (Ubuntu package)
libcroco-tools (Ubuntu package)
libcroco-0_6-3
libcroco-0_6-3-32bit
libcroco-debuginfo
libcroco-debugsource
libcroco-0_6-3-debuginfo-32bit
libcroco-0_6-3-debuginfo
libcroco-devel
libcroco
libcroco (Red Hat package)
libcroco-0_6-3-32bit-debuginfo
dev-libs/libcroco
sys-devel/gettext
gnome-base/gnome-shell
OpenShift Virtualization
VMware Tanzu Operations Manager
Dell EMC NetWorker vProxy
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-12825

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

libcroco3 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.6.13-1ubuntu0.1, 0.6.111ubuntu0.1~esm1
libcroco-tools (Ubuntu package) - addressed in versions Ubuntu Pro, 0.6.13-1ubuntu0.1, 0.6.111ubuntu0.1~esm1
libcroco-0_6-3 - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-0_6-3-32bit - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-debuginfo - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-debugsource - addressed in versions 0.6.1-122.9.1, 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-0_6-3-debuginfo-32bit - update to 0.6.11-12.6.45
libcroco-0_6-3-debuginfo - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco-devel - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco - addressed in versions 0.6.11-12.6.45, 0.6.12-150000.4.6.2, 0.6.13-3.3.1
libcroco (Red Hat package) - addressed in versions 0.6.12-4.el8_2.1, 0.6.12-6.el7_9
libcroco-0_6-3-32bit-debuginfo - addressed in versions 0.6.12-150000.4.6.2, 0.6.13-3.3.1
dev-libs/libcroco - update to 0.6.13
sys-devel/gettext - update to 0.21
OpenShift Virtualization - update to 2.4.2
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
EMC ECS - update to 3.8.0.2
gnome-base/gnome-shell - update to 3.36.7
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC NetWorker vProxy - update to 4.3.0-36
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins