CVE-2020-12825Uncontrolled Recursion in Libcroco

Severity
7.1HIGHNVD
OSV5.5
EPSS
3.7%
top 12.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateAug 13

Description

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:HExploitability: 2.8 | Impact: 4.2

Affected Packages3 packages

🔴Vulnerability Details

5
OSV
libcroco vulnerabilities2024-08-13
GHSA
GHSA-23x2-xqxm-pxwj: libcroco through 02022-05-24
OSV
libcroco vulnerabilities2022-04-26
OSV
CVE-2020-12825: libcroco through 02020-05-12
CVEList
CVE-2020-12825: libcroco through 02020-05-12

📋Vendor Advisories

4
Ubuntu
Libcroco vulnerabilities2024-08-13
Ubuntu
Libcroco vulnerabilities2022-04-26
Red Hat
libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c2020-05-12
Microsoft
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.2020-05-12

💬Community

3
Bugzilla
CVE-2020-12825 libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c [fedora-all]2020-05-13
Bugzilla
CVE-2020-12825 libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c2020-05-13
Bugzilla
CVE-2020-12825 mingw-libcroco: libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c [fedora-all]2020-05-13