ISOMAN

CVE

CVE-2016-1702

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
  2. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.html
  3. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.html
  4. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html
  5. http://www.debian.org/security/2016/dsa-3594
  6. http://www.securitytracker.com/id/1036026
  7. http://www.ubuntu.com/usn/USN-2992-1
  8. https://access.redhat.com/errata/RHSA-2016:1201
  9. https://codereview.chromium.org/1961463003
  10. https://crbug.com/609260
  11. http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
  12. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.html
  13. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.html
  14. http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html
  15. http://www.debian.org/security/2016/dsa-3594
  16. http://www.securitytracker.com/id/1036026
  17. http://www.ubuntu.com/usn/USN-2992-1
  18. https://access.redhat.com/errata/RHSA-2016:1201
  19. https://codereview.chromium.org/1961463003
  20. https://crbug.com/609260