Vulnerability CVE-2015-1295


Published: 2015-09-03   Modified: 2015-09-04

Description:
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Google -> Chrome 

 References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html
http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html
http://rhn.redhat.com/errata/RHSA-2015-1712.html
http://www.debian.org/security/2015/dsa-3351
http://www.securitytracker.com/id/1033472
https://code.google.com/p/chromium/issues/detail?id=502562
https://codereview.chromium.org/1228693002/
https://security.gentoo.org/glsa/201603-09

Copyright 2024, cxsecurity.com

 

Back to Top