CVE-2015-1278: Medium severity debian linux vulnerability
Published Jul 23, 2015
·Updated
content/browser/webcontents/webcontentsimpl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alertdialog.pdf document.
Affected Software
8 affected components
Debian Debian Linux=8.0
redhat Enterprise Linux Desktop Supplementary=6.0
redhat Enterprise Linux Server Supplementary=6.0
redhat Enterprise Linux Server Supplementary Eus=6.7z
redhat Enterprise Linux Workstation Supplementary=6.0
Google Chrome<=43.0.2357.134
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Remediation
Event History
Jul 23, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1278?
The severity of CVE-2015-1278 is classified as a moderate vulnerability.
2
How do I fix CVE-2015-1278?
To fix CVE-2015-1278, users should update Google Chrome to version 44.0.2403.89 or later.
3
What can attackers do with CVE-2015-1278?
Attackers can exploit CVE-2015-1278 to spoof URLs in modal dialogs through crafted PDF documents.
4
Which versions of Google Chrome are affected by CVE-2015-1278?
CVE-2015-1278 affects Google Chrome versions up to and including 43.0.2357.134.
5
What platforms are affected by CVE-2015-1278?
CVE-2015-1278 affects several platforms, including Debian, Red Hat, and openSUSE.