CVE-2016-5142

Publication date 7 August 2016

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code, related to NormalizeAlgorithm.cpp and SubtleCrypto.cpp.

Status

Package Ubuntu Release Status
chromium-browser 16.10 yakkety
Fixed 53.0.2785.143-0ubuntu1.1307
16.04 LTS xenial
Fixed 52.0.2743.116-0ubuntu0.16.04.1.1250
14.04 LTS trusty
Fixed 52.0.2743.116-0ubuntu0.14.04.1.1134
12.04 LTS precise Ignored
oxide-qt 16.10 yakkety
Fixed 1.16.7-0ubuntu1
16.04 LTS xenial
Fixed 1.17.7-0ubuntu0.16.04.1
14.04 LTS trusty
Fixed 1.17.7-0ubuntu0.14.04.1
12.04 LTS precise Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-3058-1
    • Oxide vulnerabilities
    • 14 September 2016

Other references


Access our resources on patching vulnerabilities