PT-2016-7310 · Google+2 · Skia+3
Publicado
2016-09-11
·
Atualizado
2017-01-07
·
CVE-2016-7395
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 53.0.2785.89 on Windows and OS X
Google Chrome versions prior to 53.0.2785.92 on Linux
Description
The issue is related to the SkPath.cpp in Skia, which does not properly validate the return values of
ChopMonoAtY calls. This allows remote attackers to cause a denial of service, resulting in uninitialized memory access and application crash, or possibly have other unspecified impact via crafted graphics data.Recommendations
For Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, update to version 53.0.2785.89 or later.
For Google Chrome versions prior to 53.0.2785.92 on Linux, update to version 53.0.2785.92 or later.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Opera
Skia