CVE-2015-1257

EUVD-2015-1398
platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted document.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
8.0
googlechrome
𝑥
≤ 42.0.2311.152
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
precise
ignored
trusty
Fixed 43.0.2357.81-0ubuntu0.14.04.1.1089
released
utopic
Fixed 43.0.2357.81-0ubuntu0.14.10.1.1131
released
vivid
Fixed 43.0.2357.81-0ubuntu0.15.04.1.1170
released
wily
Fixed 43.0.2357.81-0ubuntu1.1179
released
oxide-qt
precise
dne
trusty
Fixed 1.7.8-0ubuntu0.14.04.1
released
utopic
Fixed 1.7.8-0ubuntu0.14.10.1
released
vivid
Fixed 1.7.8-0ubuntu0.15.04.1
released
wily
Fixed 1.7.8-0ubuntu1
released