First published: Mon Mar 09 2015(Updated: )
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <=40.0.2214.115 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.6.z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1230 has a medium severity level due to its potential to cause denial of service conditions.
To fix CVE-2015-1230, update Google Chrome to version 41.0.2272.76 or later.
CVE-2015-1230 affects Google Chrome versions prior to 41.0.2272.76 and specific versions of Red Hat and Ubuntu Linux.
CVE-2015-1230 can lead to denial of service and may allow attackers to execute unspecified malicious actions via JavaScript.
You can check if you are at risk for CVE-2015-1230 by verifying the version of your Google Chrome browser and related affected software.