Upstream information
Description
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 4.3 |
Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
- openSUSE-SU-2015:0748-1, published Wed, 22 Apr 2015 11:04:47 +0200 (CEST)
- openSUSE-SU-2015:1887-1, published Mon, 2 Nov 2015 16:41:27 +0100 (CET)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE 13.1 |
| Patchnames: openSUSE-2015-320 |
openSUSE Leap 15.0 |
| Patchnames: openSUSE Leap 15.0 GA chromium |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA chromedriver |