The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
| Software | From | Fixed in |
|---|---|---|
| gnome / libcroco | 0.6.12 | 0.6.12.x |
| opensuse / leap | 42.3 | 42.3.x |