libcroco: Undefined behavior issue in cr_tknzr_parse_rgb function
Published Apr 19, 2017
7.8
HIGHCVSS 3.1
EPSS 1.97%
Description
The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
libcroco
Will not fix
Red Hat Enterprise Linux 6
libcroco
Will not fix
Red Hat Enterprise Linux 7
libcroco
Will not fix
Red Hat Enterprise Linux 9
libcroco
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libcroco | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libcroco | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libcroco | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | libcroco | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 22, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.97% (0.01966) | 79.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.97% (0.01966) | 77.70th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.36% (0.00355) | 54.87th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.45% (0.03454) | 78.98th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.36% (0.00355) | 55.65th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.76% (0.00757) | 81.76th | v3 (v2023.03.01) |
| May 1, 2024 | 0.70% (0.00697) | 80.02th | v3 (v2023.03.01) |
| Mar 13, 2024 | 0.69% (0.00689) | 79.63th | v3 (v2023.03.01) |
| Sep 4, 2023 | 0.69% (0.00689) | 77.62th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.49% (0.00486) | 72.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.41% (0.00412) | 69.88th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.32% (0.01319) | 71.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.32% (0.01319) | 44.98th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.26% (0.02262) | 50.78th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.26% (0.02262) | 0.00th | v1 |
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2017/04/24/2 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7961 Vendor Advisory
- https://blogs.gentoo.org/ago/2017/04/17/libcroco-heap-overflow-and-undefined-behavior/ x_refsource_MISCExploitPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1450068 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1034482 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://git.gnome.org/browse/libcroco/commit/?id=9ad72875e9f08e4c519ef63d44cdbd94aa9504f7 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7961
- https://security.gentoo.org/glsa/201707-13 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-7961
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html | vendor-advisoryx_refsource_SUSE | |
| http://openwall.com/lists/oss-security/2017/04/24/2 | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-7961 | Vendor Advisory | |
| https://blogs.gentoo.org/ago/2017/04/17/libcroco-heap-overflow-and-undefined-behavior/ | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1450068 | Issue Tracking | |
| https://bugzilla.suse.com/show_bug.cgi?id=1034482 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://git.gnome.org/browse/libcroco/commit/?id=9ad72875e9f08e4c519ef63d44cdbd94aa9504f7 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-7961 | ||
| https://security.gentoo.org/glsa/201707-13 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-7961 |
Change history (0)
No recorded changes yet.