4.3

CVE-2015-1241

Exploit
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version < 42.0.2311.90
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Version 12.0
Redhat ≫ Enterprise Linux Eus Version 6.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.21% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-1021 Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
Third Party Advisory
Mitigation
https://security.gentoo.org/glsa/201506-04
Third Party Advisory
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
Release Notes
http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
Third Party Advisory
Mitigation
http://rhn.redhat.com/errata/RHSA-2015-0816.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3238
Third Party Advisory
http://www.securitytracker.com/id/1032209
Third Party Advisory
Broken Link
VDB Entry
http://ubuntu.com/usn/usn-2570-1
Third Party Advisory
https://code.google.com/p/chromium/issues/detail?id=418402
Vendor Advisory
Exploit
Issue Tracking
https://codereview.chromium.org/628763003
Vendor Advisory
Issue Tracking
https://codereview.chromium.org/660663002
Vendor Advisory
Issue Tracking
https://codereview.chromium.org/717573004
Vendor Advisory
Issue Tracking
https://codereview.chromium.org/868123002
Vendor Advisory
Issue Tracking