The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
| Software | From | Fixed in |
|---|---|---|
| gnome / libcroco | 0.6.12 | 0.6.12.x |
| opensuse / leap | 42.3 | 42.3.x |