Related Vulnerabilities: CVE-2016-5161  

The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that leverages "type confusion" in the StylePropertySerializer class.

Severity Medium

Remote Yes

Type Information disclosure

Description

The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that leverages "type confusion" in the StylePropertySerializer class.

AVG-109 qt5-webengine 5.7.0-7 5.7.1-1 Critical Fixed

17 Dec 2016 ASA-201612-18 AVG-109 qt5-webengine Critical multiple issues

https://bugs.chromium.org/p/chromium/issues/detail?id=622420