Bug 1245955 (CVE-2015-5605)

Summary: CVE-2015-5605 chromium-browser: v8 denial of service
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: tpopela
Target Milestone: ---Keywords: Reopened, Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Chrome 44.0.2403.89 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-07-28 06:21:21 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1245437, 1245438    
Bug Blocks: 1245439    

Description Martin Prpič 2015-07-23 08:27:43 UTC
A vulnerability was found in Google Chrome up to 43.0.2357.134. It has been classified as problematic. Affected is an unknown function of the component v8. The manipulation with an unknown input leads to a denial of service vulnerability.

Additional information:

http://www.scip.ch/en/?vuldb.76794

Comment 1 Huzaifa S. Sidhpurwala 2015-07-25 03:00:27 UTC
This issue was is tracked in chromium tracker via the following bug:

https://code.google.com/p/chromium/issues/detail?id=512110
https://code.google.com/p/chromium/issues/detail?id=469480

This is fixed in google-chrome 44.0.2403.89 but was not listed in the chrome advisory web page.

Comment 2 errata-xmlrpc 2015-07-27 09:09:37 UTC
This issue has been addressed in the following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2015:1499 https://rhn.redhat.com/errata/RHSA-2015-1499.html