Upstream information
Description
core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 7.5 |
Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
SUSE Security Advisories:
- openSUSE-SU-2015:0969-1, published Fri, 29 May 2015 17:06:19 +0200 (CEST)
- openSUSE-SU-2015:1877-1, published Mon, 2 Nov 2015 16:36:06 +0100 (CET)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Leap 15.0 |
| Patchnames: openSUSE Leap 15.0 GA chromium-66.0.3359.170-lp150.1.1 |
openSUSE Leap 15.2 |
| Patchnames: openSUSE Leap 15.2 GA chromium-83.0.4103.97-lp152.1.1 |
openSUSE Leap 15.3 |
| Patchnames: openSUSE Leap 15.3 GA chromium-90.0.4430.212-bp153.1.1 |
openSUSE Leap 15.4 |
| Patchnames: openSUSE Leap 15.4 GA chromium-101.0.4951.64-bp154.1.2 |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA chromedriver-55.0.2883.75-3.1 openSUSE Tumbleweed GA ungoogled-chromium-113.0.5672.92-1.1 |
SUSE Timeline for this CVE
CVE page created: Wed May 20 12:27:21 2015CVE page last modified: Fri Jun 30 15:25:54 2023