All errata/sisyphus/ALT-PU-2015-1729-1
ALT-PU-2015-1729-1

Package update chromium in branch sisyphus

Version44.0.2403.157-alt1
Published2015-08-29
Max severityCRITICAL
Severity:

Closed issues (63)

BDU:2015-10875
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10876
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10877
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10878
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10879
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10880
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-10881
HIGH7.5

Уязвимости браузера Google Chrome, позволяющие нарушителю вызвать отказ в обслуживании

Published: 2015-07-31Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11018
MEDIUM6.8

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-08-18Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BDU:2015-11019
MEDIUM6.8

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-08-18Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BDU:2015-11020
MEDIUM6.8

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-08-18Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BDU:2015-11021
MEDIUM6.8

Уязвимость браузера Google Chrome, позволяющая нарушителю выполнить произвольный код

Published: 2015-08-18Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BDU:2015-11027
MEDIUM5.0

Уязвимость операционной системы Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-08-18Modified: 2021-03-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
References
BDU:2015-11275
MEDIUM6.4

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа или вызвать отказ в обслуживании

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 6.4
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:P
References
BDU:2015-11276
MEDIUM5.0

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
References
BDU:2015-11277
MEDIUM5.0

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
References
BDU:2015-11278
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11279
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-09-16Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11280
MEDIUM5.0

Уязвимость браузера Google Chrome, позволяющая нарушителю подменить значок SSL

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
References
BDU:2015-11281
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11282
MEDIUM4.3

Уязвимость браузера Google Chrome, позволяющая нарушителю перенаправить пользователя на произвольный URL

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
References
BDU:2015-11283
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-09-16Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11284
MEDIUM5.0

Уязвимость браузера Google Chrome, позволяющая нарушителю получить доступ к защищаемой информации

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
References
BDU:2015-11285
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11330
HIGH7.5

Уязвимости браузера Google Chrome, позволяющие нарушителю вызвать отказ в обслуживании

Published: 2015-09-16Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11331
HIGH7.5

Уязвимость браузера Google Chrome, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BDU:2015-11332
MEDIUM6.8

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BDU:2015-11333
MEDIUM4.3

Уязвимость браузера Google Chrome, позволяющая нарушителю подменить содержимое окна браузера

Published: 2015-09-15Modified: 2021-03-23
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
References
CVE-2015-1270
MEDIUM6.8

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVE-2015-1272
HIGH7.5

Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelHost data structure during Blink shutdown, related to content/browser/gpu/browser_gpu_channel_host_factory.cc and content/renderer/render_thread_impl.cc.

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-1283
MEDIUM6.8

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References
CVE-2015-1284
HIGH7.5

The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code that makes many createElement calls for IFRAME elements.

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-1286
MEDIUM4.3

Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CVE-2015-1289
HIGH7.5

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

Published: 2015-07-23Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CVE-2015-1295
HIGH7.5

Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-1296
MEDIUM5.0

The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CVE-2015-1299
HIGH7.5

Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp and Timer.cpp.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-1300
MEDIUM5.0

The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CVE-2015-1301
HIGH7.5

Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CVE-2015-6580
HIGH7.5

Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVE-2015-6582
MEDIUM6.8

The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVE-2015-6583
MEDIUM4.3

Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc.

Published: 2015-09-03Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N