Bug#960527: libcroco: CVE-2020-12825

2020-05-13 Thread Salvatore Bonaccorso
Hi Simon, On Wed, May 13, 2020 at 05:02:32PM +0100, Simon McVittie wrote: > On Wed, 13 May 2020 at 17:21:44 +0200, Salvatore Bonaccorso wrote: > > CVE-2020-12825[0]: > > | libcroco through 0.6.13 has excessive recursion in > > | cr_parser_parse_any_core in cr-parser.c, leading to stack consumption

Bug#960527: libcroco: CVE-2020-12825

2020-05-13 Thread Simon McVittie
On Wed, 13 May 2020 at 17:21:44 +0200, Salvatore Bonaccorso wrote: > CVE-2020-12825[0]: > | libcroco through 0.6.13 has excessive recursion in > | cr_parser_parse_any_core in cr-parser.c, leading to stack consumption. Mitigation: here are the only things in >= stable that depend on libcroco: - gn

Bug#960527: libcroco: CVE-2020-12825

2020-05-13 Thread Salvatore Bonaccorso
Source: libcroco Version: 0.6.13-1 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/libcroco/-/issues/8 Hi, The following vulnerability was published for libcroco. CVE-2020-12825[0]: | libcroco through 0.6.13 has excessive recursion in | cr_parser_parse_any_c