PT-2016-7310 · Google+2 · Skia+3
Published
2016-09-11
·
Updated
2017-01-07
·
CVE-2016-7395
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 53.0.2785.89 on Windows and OS X
Google Chrome versions prior to 53.0.2785.92 on Linux
Description
The issue is related to the SkPath.cpp in Skia, which does not properly validate the return values of
ChopMonoAtY calls. This allows remote attackers to cause a denial of service, resulting in uninitialized memory access and application crash, or possibly have other unspecified impact via crafted graphics data.Recommendations
For Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, update to version 53.0.2785.89 or later.
For Google Chrome versions prior to 53.0.2785.92 on Linux, update to version 53.0.2785.92 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Opera
Skia