CVE-2015-1267
Publication date 26 June 2015
Last updated 24 July 2024
Ubuntu priority
Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
14.04 LTS trusty |
Fixed 43.0.2357.130-0ubuntu0.14.04.1.1092
|
|
oxide-qt | ||
14.04 LTS trusty |
Fixed 1.7.9-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2652-1
- Oxide vulnerabilities
- 30 June 2015