MGASA-2015-0164

Source
https://advisories.mageia.org/MGASA-2015-0164.html
Import Source
https://advisories.mageia.org/MGASA-2015-0164.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0164
Upstream
  • CVE-2015-1235
  • CVE-2015-1236
  • CVE-2015-1237
  • CVE-2015-1238
  • CVE-2015-1240
  • CVE-2015-1241
  • CVE-2015-1242
  • CVE-2015-1244
  • CVE-2015-1245
  • CVE-2015-1246
  • CVE-2015-1247
  • CVE-2015-1248
  • CVE-2015-1249
  • CVE-2015-3333
Published
2015-04-23T21:14:25Z
Modified
2026-04-16T06:24:17Z
Summary
Updated chromium-browser-stable packages fix security vulnerabilities
Details

Chromium-browser 42.0.2311.90 fixes several security issues, among others a cross-origin-bypass in HTML parser (CVE-2015-1235), a cross-origin-bypass in Blink (CVE-2015-1236), a use-after-free in IPC (CVE-2015-1237), an out-of-bounds write in Skia (CVE-2015-1238), an out-of-bounds read in WebGL (CVE-2015-1240), Tap-Jacking (CVE-2015-1241), type confusion in V8 (CVE-2015-1242), HSTS bypass in WebSockets (CVE-2015-1244), a use-after-free in PDFium (CVE-2015-1245), an out-of-bounds read in Blink (CVE-2015-1246), scheme issues in OpenSearch, (CVE-2015-1247), and a SafeBrowsing bypass (CVE-2015-1248). Also included are various fixes from internal audits, fuzzing and other initiatives (CVE-2015-1249), and multiple vulnerabilities in V8 have been fixed at the tip of the 4.2 branch (currently 4.2.77.14) (CVE-2015-3333).

References
Credits

Affected packages

Mageia:4 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
42.0.2311.90-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0164.json"