CVE-2016-1637
published 2016-03-06CVE-2016-1637: The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations…
PriorityP425medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.12%
63.0th percentile
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 48.0.2564.116 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ph2v-xqxg-m4w5: The SkATan2_255 function in effects/gradients/SkSweepGradient
ghsa_unreviewed·2022-05-17
CVE-2016-1637 [MEDIUM] CWE-200 GHSA-ph2v-xqxg-m4w5: The SkATan2_255 function in effects/gradients/SkSweepGradient
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
OSV
oxide-qt vulnerabilities
osv·2016-03-10·CVSS 8.8
CVE-2016-1630 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that the ContainerNode::parserRemoveChild function in
Blink mishandled widget updates in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1630)
It was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun
function in Chromium mishandled nested message loops. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1631)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit these to cause a denial of service via renderer
OSV
CVE-2016-1637: The SkATan2_255 function in effects/gradients/SkSweepGradient
osv·2016-03-05·CVSS 6.5
CVE-2016-1637 [MEDIUM] CVE-2016-1637: The SkATan2_255 function in effects/gradients/SkSweepGradient
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-03-10·CVSS 8.8
CVE-2016-1630 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that the ContainerNode::parserRemoveChild function in
Blink mishandled widget updates in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1630)
It was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun
function in Chromium mishandled nested message loops. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1631)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacker could potentia
Red Hat
chromium-browser: information leak in Skia
vendor_redhat·2016-03-02·CVSS 6.5
CVE-2016-1637 [MEDIUM] CWE-200 chromium-browser: information leak in Skia
chromium-browser: information leak in Skia
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1637 chromium-browser: information leak in Skia
bugzilla·2016-03-03·CVSS 6.5
CVE-2016-1637 [MEDIUM] CVE-2016-1637 chromium-browser: information leak in Skia
CVE-2016-1637 chromium-browser: information leak in Skia
A information leak flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=555544
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
pcre: Heap buffer overflow in pcretest causing infinite loop (8.39/15)
bugzilla·2016-02-29
pcre: Heap buffer overflow in pcretest causing infinite loop (8.39/15)
pcre: Heap buffer overflow in pcretest causing infinite loop (8.39/15)
Heap-based buffer overread caused by specially crafted input triggering infinite loop in pcretest.c was found affecting pcre 8.38. pcretest went into loop if global matching was requested with an ovector size less than 2.
Upstream bug:
https://bugs.exim.org/show_bug.cgi?id=1777
Upstream patch:
http://vcs.pcre.org/pcre?view=revision&revision=1637
CVE request:
http://seclists.org/oss-sec/2016/q1/460
Discussion:
Acknowledgments:
Name: Adam Mariš (Red Hat)
---
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1312786]
---
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1312789]
---
Created mingw-glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1312791]
Af
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://www.debian.org/security/2016/dsa-3507http://www.securityfocus.com/bid/84008http://www.securitytracker.com/id/1035185http://www.ubuntu.com/usn/USN-2920-1https://code.google.com/p/chromium/issues/detail?id=555544https://codereview.chromium.org/1506913002https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://www.debian.org/security/2016/dsa-3507http://www.securityfocus.com/bid/84008http://www.securitytracker.com/id/1035185http://www.ubuntu.com/usn/USN-2920-1https://code.google.com/p/chromium/issues/detail?id=555544https://codereview.chromium.org/1506913002https://security.gentoo.org/glsa/201603-09
2016-03-06
Published