Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 7: 2021-0333 Moderate: libcroco Stack Consumption Issue

mageia
Calendar Grey July 10, 2021
Dist Mageia Esm H88
The latest versions of libcroco and gettext have resolved a significant stack overflow vulnerability on Mageia. Update today!
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption (CVE-2020-12825)

Summary

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption (CVE-2020-12825).

References

- https://bugs.mageia.org/show_bug.cgi?id=27108

- https://access.redhat.com/errata/RHSA-2020:4072

- https://gitlab.gnome.org/Archive/libcroco/-/issues/8

- https://www.cve.org/CVERecord?id=CVE-2020-12825

Resolution

SRPMS

- 7/core/libcroco-0.6.13-1.2.mga7

- 7/core/gettext-0.19.8.1-4.1.mga7

Publication date: 10 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0333.html
Type: security
CVE: CVE-2020-12825

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here