CVE-2015-8664

Publication date 23 December 2015

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a different vulnerability than CVE-2015-6792.

Status

Package Ubuntu Release Status
chromium-browser 15.10 wily
Fixed 47.0.2526.106-0ubuntu0.15.10.1.1218
15.04 vivid
Fixed 47.0.2526.106-0ubuntu0.15.04.1.1192
14.04 LTS trusty
Fixed 47.0.2526.106-0ubuntu0.14.04.1.1107
12.04 LTS precise Ignored
oxide-qt 15.10 wily
Fixed 1.11.4-0ubuntu0.15.10.1
15.04 vivid
Fixed 1.11.4-0ubuntu0.15.04.1
14.04 LTS trusty
Fixed 1.11.4-0ubuntu0.14.04.1
12.04 LTS precise Not in release

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H