CVE-2015-1294

Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an infinite result during an inversion calculation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 44.0.2403
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
precise
ignored
trusty
Fixed 45.0.2454.85-0ubuntu0.14.04.1.1097
released
vivid
Fixed 45.0.2454.85-0ubuntu0.15.04.1.1181
released
wily
Fixed 45.0.2454.85-0ubuntu1.1198
released
oxide-qt
precise
dne
trusty
Fixed 1.9.1-0ubuntu0.14.04.2
released
vivid
Fixed 1.9.1-0ubuntu0.15.04.1
released
wily
Fixed 1.9.1-0ubuntu1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
chromium-browser
RHEL 6
0:45.0.2454.85-2.el6
fixed