SB2015052015 - Permissions, Privileges, and Access Controls in Debian Linux



SB2015052015 - Permissions, Privileges, and Access Controls in Debian Linux

Published: May 20, 2015 Updated: August 9, 2020

Security Bulletin ID SB2015052015
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-1254)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.


Remediation

Install update from vendor's website.