libcroco: Multiple vulnerabilities Multiple vulnerabilities have been found in libcroco, the worst of which may have unspecified impacts. libcroco 2017-07-09 2017-08-06 618012 remote 0.6.12-r1 0.6.12-r1

libcroco is a standalone CSS2 parsing and manipulation library.

Multiple vulnerabilities have been discovered in libcroco. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to open a specially crafted CSS file possibly resulting in a Denial of Service condition or other unspecified impacts.

There is no known workaround at this time.

All libcroco users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libcroco-0.6.12-r1"
CVE-2017-7960 CVE-2017-7961 BlueKnight whissi