The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
| Software | From | Fixed in |
|---|---|---|
| gnome / libcroco | 0.6.12 | 0.6.12.x |
| gnome / libcroco | 0.6.11 | 0.6.11.x |