MGASA-2015-0062

Source
https://advisories.mageia.org/MGASA-2015-0062.html
Import Source
https://advisories.mageia.org/MGASA-2015-0062.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0062
Upstream
  • CVE-2015-1209
  • CVE-2015-1210
  • CVE-2015-1211
  • CVE-2015-1212
Published
2015-02-11T20:47:51Z
Modified
2026-04-16T06:25:22.997667672Z
Summary
Updated chromium-browser-stable packages fix security vulnerabilities
Details

Updated chromium-browser packages fix security vulnerabilities:

Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor (CVE-2015-1209).

The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site (CVE-2015-1210).

The OriginCanAccessServiceWorkers function in content/browser/serviceworker/serviceworkerdispatcherhost.cc in Google Chrome before 40.0.2214.111 does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI (CVE-2015-1211).

Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 allow attackers to cause a denial of service or possibly have other impact via unknown vectors (CVE-2015-1212).

References
Credits

Affected packages

Mageia:4 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
40.0.2214.111-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0062.json"