First published: Thu Jul 23 2015(Updated: )
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.
Credit: chrome-cve-admin@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium-browser | ||
openSUSE openSUSE | =13.1 | |
openSUSE openSUSE | =13.2 | |
Google Chrome | <=43.0.2357.134 | |
Redhat Enterprise Linux Desktop Supplementary | =6.0 | |
Redhat Enterprise Linux Server Supplementary | =6.0 | |
Redhat Enterprise Linux Server Supplementary Eus | =6.7z | |
Redhat Enterprise Linux Workstation Supplementary | =6.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2015-1287.
CVE-2015-1287 has a severity of 4.3 (medium).
CVE-2015-1287 allows remote attackers to bypass the Same Origin Policy via a crafted website.
Google Chrome versions before 44.0.2403.89 are affected by CVE-2015-1287.
To fix CVE-2015-1287, update Google Chrome to version 44.0.2403.89 or later.