REDHAT-BUG-1537817: Integer Overflow
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5095
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1537817?
The severity of REDHAT-BUG-1537817 is considered high due to the potential for exploitable crashes.
How do I fix REDHAT-BUG-1537817?
To fix REDHAT-BUG-1537817, update the Google Skia library to the latest version where the vulnerability is addressed.
What systems are affected by REDHAT-BUG-1537817?
REDHAT-BUG-1537817 affects systems running the Skia library with at least 8 GB of RAM.
What are the consequences of not mitigating REDHAT-BUG-1537817?
Not mitigating REDHAT-BUG-1537817 can lead to crashes and potential exploitation through uninitialized memory.
Is there a workaround for REDHAT-BUG-1537817?
Currently, there are no known workarounds for REDHAT-BUG-1537817; updating is recommended.