CVE-2015-1274: Medium severity debian linux vulnerability
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to downloadcommands.cc and downloadprefs.cc.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1274?
CVE-2015-1274 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2015-1274?
To fix CVE-2015-1274, update Google Chrome to version 44.0.2403.89 or later.
Which versions of Google Chrome are affected by CVE-2015-1274?
CVE-2015-1274 affects all versions of Google Chrome prior to 44.0.2403.89.
Can CVE-2015-1274 impact my system security?
Yes, CVE-2015-1274 can significantly impact system security by allowing malicious files to be executed.
Is my Linux distribution vulnerable to CVE-2015-1274?
Yes, distributions such as Debian, openSUSE, and Red Hat that run affected versions of Google Chrome are vulnerable to CVE-2015-1274.