Описание
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-apps/xenial | ignored | in multiverse |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [abandoned]] |
| esm-infra/focal | DNE | |
| focal | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 55.0.2883.87-0ubuntu1 |
| bionic | released | 55.0.2883.87-0ubuntu1 |
| cosmic | released | 55.0.2883.87-0ubuntu1 |
| devel | released | 55.0.2883.87-0ubuntu1 |
| disco | released | 55.0.2883.87-0ubuntu1 |
| eoan | released | 55.0.2883.87-0ubuntu1 |
| esm-apps/noble | released | 55.0.2883.87-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [53.0.2785.143-0ubuntu0.14.04.1.1142]] |
| esm-infra/focal | DNE | focal was released [55.0.2883.87-0ubuntu1] |
| focal | released | 55.0.2883.87-0ubuntu1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 50.1.0+build2-0ubuntu1 |
| bionic | not-affected | 50.1.0+build2-0ubuntu1 |
| cosmic | not-affected | 50.1.0+build2-0ubuntu1 |
| devel | not-affected | 50.1.0+build2-0ubuntu1 |
| disco | not-affected | 50.1.0+build2-0ubuntu1 |
| eoan | not-affected | 50.1.0+build2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [50.1.0+build2-0ubuntu0.14.04.1]] |
| esm-infra/focal | DNE | |
| focal | not-affected | 50.1.0+build2-0ubuntu1 |
| groovy | not-affected | 50.1.0+build2-0ubuntu1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 1.17.7-0ubuntu1 |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1.17.7-0ubuntu0.14.04.1]] |
| esm-infra/focal | DNE | |
| esm-infra/xenial | released | 1.17.7-0ubuntu0.16.04.1 |
| focal | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | |
| bionic | not-affected | |
| cosmic | not-affected | |
| devel | not-affected | |
| disco | not-affected | |
| eoan | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| esm-infra/focal | DNE | |
| focal | not-affected | |
| groovy | not-affected |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needs-triage] |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-apps/xenial | needed | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
| esm-infra/focal | DNE | |
| focal | DNE |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Wi ...
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3