CVE-2020-12825: High severity ibm infosphere guardium z/os vulnerability
Last updated 13 August 2024
Other sources
Libcroco is vulnerable to a denial of service, caused by excessive recursion in crparserparseanycore in cr-parser.c. By persuading a victim to open a specially-crafted CSS file, a remote attacker could exploit this vulnerability to cause stack consumption.
— IBM
libcroco through 0.6.13 has excessive recursion in crparserparseanycore in cr-parser.c, leading to stack consumption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-12825?
CVE-2020-12825 is a vulnerability in Libcroco that could cause a denial of service due to excessive recursion in cr_parser_parse_any_core in cr-parser.c.
How can this vulnerability be exploited?
This vulnerability can be exploited by convincing a victim to open a specially-crafted CSS file.
What are the affected versions of IBM Security Guardium?
IBM Security Guardium versions 10.5 to 11.3 are affected by this vulnerability.
What is the severity of CVE-2020-12825?
The severity of CVE-2020-12825 is classified as high with a CVSS score of 7.1.
How can I mitigate CVE-2020-12825?
To mitigate CVE-2020-12825, users should update Libcroco to a version that includes the fix for the vulnerability.