Upstream information
Description
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)."SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 4.3 |
Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
National Vulnerability Database | |
---|---|
Base Score | 6.1 |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Access Vector | Network |
Access Complexity | Low |
Privileges Required | None |
User Interaction | Required |
Scope | Changed |
Confidentiality Impact | Low |
Integrity Impact | Low |
Availability Impact | None |
CVSSv3 Version | 3 |
- SUSE-SU-2016:2251-1, published Tue, 6 Sep 2016 21:09:12 +0200 (CEST)
- openSUSE-SU-2016:2250-1, published Tue, 6 Sep 2016 21:08:26 +0200 (CEST)
- openSUSE-SU-2016:2296-1, published Tue, 13 Sep 2016 13:09:18 +0200 (CEST)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Package Hub for SUSE Linux Enterprise 12 |
| Patchnames: 5568 |
openSUSE Leap 15.0 |
| Patchnames: openSUSE Leap 15.0 GA chromium |
openSUSE Leap 42.1 |
| Patchnames: 5568 |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA chromedriver |