CVE-2015-1285: XSS
Last updated 24 July 2024
Other sources
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-1285?
CVE-2015-1285 is a vulnerability in the XSS auditor in Blink, affecting Google Chrome before version 44.0.2403.89.
How severe is CVE-2015-1285?
CVE-2015-1285 has a severity rating of medium (5).
What software is affected by CVE-2015-1285?
Google Chrome versions before 44.0.2403.89 are affected by CVE-2015-1285.
How can I fix CVE-2015-1285?
Update Google Chrome to version 44.0.2403.89 or later to fix CVE-2015-1285.
Where can I find more information about CVE-2015-1285?
More information about CVE-2015-1285 can be found at the following references: [CVE-2015-1285](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1285), [Google Chrome Releases](http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html), [Ubuntu Security Notice USN-2677-1](https://ubuntu.com/security/notices/USN-2677-1).