CVE-2016-1649 PUBLISHED

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted shader stages.

EPSS 2.81% · 86.0th percentile

Risk Scores

EPSS Score
2.81%
86.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSoxide-qt1.0.0~bzr501-0ubuntu2, 1.13.6-0ubuntu0.14.04.1, 1.12.7-0ubuntu0.14.04.1
Ubuntu:16.04:LTSoxide-qt1.13.6-0ubuntu1, 0, 1.9.5-0ubuntu1
Ubuntu:14.04:LTSchromium-browser41.0.2272.76-0ubuntu0.14.04.1.1076, 40.0.2214.111-0ubuntu0.14.04.1.1069, 40.0.2214.94-0ubuntu0.14.04.1.1068
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218

Timeline

References

Open in Interactive Console →