DSA-3376-1 chromium-browser -- chromium-browserID: oval:org.secpod.oval:def:602250 | Date: (C)2015-10-21 (M)2023-11-13 |
Class: PATCH | Family: unix |
Several vulnerabilities have been discovered in the chromium web browser. CVE-2015-1303 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in the DOM implementation. CVE-2015-1304 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in the v8 javascript library. CVE-2015-6755 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in blink/webkit. CVE-2015-6756 A use-after-free issue was found in the pdfium library. CVE-2015-6757 Collin Payne found a use-after-free issue in the ServiceWorker implementation. CVE-2015-6758 Atte Kettunen found an issue in the pdfium library. CVE-2015-6759 Muneaki Nishimura discovered an information leak. CVE-2015-6760 Ronald Crane discovered a logic error in the ANGLE library involving lost device events. CVE-2015-6761 Aki Helin and Khalil Zhani discovered a memory corruption issue in the ffmpeg library. CVE-2015-6762 Muneaki Nishimura discovered a way to bypass the Same Origin Policy in the CSS implementation. CVE-2015-6763 The chrome 46 development team found and fixed various issues during internal auditing. Also multiple issues were fixed in the v8 javascript library, version 4.6.85.23.