#VU19192 Buffer overflow in libcroco - CVE-2017-8834
Published: July 16, 2019
libcroco
Gnome Development Team
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the "cr_tknzr_parse_comment" function, as defined in the "src/cr-tknzr.c" file. A remote attacker can persuade a user to access a CSS file that submits malicious input to the system, trigger memory corruption and cause a DoS condition on the affected system.