All errata/sisyphus/ALT-PU-2015-1815-1
ALT-PU-2015-1815-1

Package update chromium in branch sisyphus

Version45.0.2454.101-alt1
Published2015-09-29
Max severityHIGH
Severity:

Closed issues (4)

BDU:2015-11682
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

Published: 2015-10-29Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11683
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

Published: 2015-10-29Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CVE-2015-1303
HIGH7.5

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containing an IFRAME element.

Published: 2015-10-12Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-1304
HIGH7.5

object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.

Published: 2015-10-12Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P