Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-1211
HistoryFeb 06, 2015 - 12:00 a.m.

CVE-2015-1211

2015-02-0600:00:00
ubuntu.com
ubuntu.com
13

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.009

Percentile

83.2%

The OriginCanAccessServiceWorkers function in
content/browser/service_worker/service_worker_dispatcher_host.cc in Google
Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before
40.0.2214.109 on Android does not properly restrict the URI scheme during a
ServiceWorker registration, which allows remote attackers to gain
privileges via a filesystem: URI.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchchromium-browser< 40.0.2214.111-0ubuntu0.14.04.1.1069UNKNOWN
ubuntu14.10noarchchromium-browser< 40.0.2214.111-0ubuntu0.14.10.1.1111UNKNOWN
ubuntu15.04noarchchromium-browser< 40.0.2214.111-0ubuntu1.1121UNKNOWN
ubuntu15.10noarchchromium-browser< 40.0.2214.111-0ubuntu1.1121UNKNOWN
ubuntu14.04noarchoxide-qt< 1.4.3-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchoxide-qt< 1.4.3-0ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchoxide-qt< 1.5.3-0ubuntu2UNKNOWN
ubuntu15.10noarchoxide-qt< 1.5.3-0ubuntu2UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.009

Percentile

83.2%