{ "id": "CVE-2015-1257", "sourceIdentifier": "cve-coordination@google.com", "published": "2015-05-20T10:59:09.760", "lastModified": "2017-01-03T02:59:47.163", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted document." }, { "lang": "es", "value": "platform/graphics/filters/FEColorMatrix.cpp en la implementaci\u00f3n SVG en Blink, utilizado en Google Chrome anterior a 43.0.2357.65, no maneja correctamente un n\u00famero insuficiente de valores en un filtro feColorMatrix, lo que permite a atacantes remotosw causar una denegaci\u00f3n de servicio (desbordamiento de contenedor) o posiblemente tener otro impacto no especificado a trav\u00e9s de un documento manipulado." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 7.5 }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-119" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*", "versionEndIncluding": "42.0.2311.152", "matchCriteriaId": "6F238C75-E24A-406F-BEB5-8758C8FE9603" } ] } ] } ], "references": [ { "url": "http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html", "source": "cve-coordination@google.com", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html", "source": "cve-coordination@google.com" }, { "url": "http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html", "source": "cve-coordination@google.com" }, { "url": "http://www.debian.org/security/2015/dsa-3267", "source": "cve-coordination@google.com" }, { "url": "http://www.securityfocus.com/bid/74723", "source": "cve-coordination@google.com" }, { "url": "http://www.securitytracker.com/id/1032375", "source": "cve-coordination@google.com" }, { "url": "https://code.google.com/p/chromium/issues/detail?id=468519", "source": "cve-coordination@google.com" }, { "url": "https://security.gentoo.org/glsa/201506-04", "source": "cve-coordination@google.com" }, { "url": "https://src.chromium.org/viewvc/blink?view=rev&revision=193571", "source": "cve-coordination@google.com" }, { "url": "https://src.chromium.org/viewvc/blink?view=rev&revision=193911", "source": "cve-coordination@google.com" } ] }