HIGH
chromium-browser: Use-after-free in Skia
Published Sep 3, 2015
7.5
HIGHCVSS 2.0
EPSS 1.59%
Description
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an infinite result during an inversion calculation.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:45.0.2454.85-2.el6
Fixed · RHSA-2015:1712
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:45.0.2454.85-2.el6 | Fixed | RHSA-2015:1712 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1712.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2015/dsa-3351 vendor-advisoryx_refsource_DEBIAN
- http://www.securitytracker.com/id/1033472 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2015-1294 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1259162 Issue Tracking
- https://code.google.com/p/chromium/issues/detail?id=492263 x_refsource_CONFIRM
- https://codereview.chromium.org/1188433011/ x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2015-1294
- https://security.gentoo.org/glsa/201603-09 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-1294
| Link | Providers | Tags |
|---|---|---|
| http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html | x_refsource_CONFIRM | |
| http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html | vendor-advisoryx_refsource_SUSE | |
| http://rhn.redhat.com/errata/RHSA-2015-1712.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.debian.org/security/2015/dsa-3351 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securitytracker.com/id/1033472 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2015-1294 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1259162 | Issue Tracking | |
| https://code.google.com/p/chromium/issues/detail?id=492263 | x_refsource_CONFIRM | |
| https://codereview.chromium.org/1188433011/ | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-1294 | ||
| https://security.gentoo.org/glsa/201603-09 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2015-1294 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 3, 2015
Updated Aug 6, 2024
Reserved Jan 21, 2015
Link CVE-2015-1294
CISA Vulnrichment
Updated n/a