Bug 1280298 - (CVE-2015-1302) CVE-2015-1302 chromium-browser: information leak in PDF viewer
CVE-2015-1302 chromium-browser: information leak in PDF viewer
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20151110,repo...
: Security
Depends On: 1266411 1266412 1280305 1280306
Blocks: 1280299
  Show dependency treegraph
 
Reported: 2015-11-11 07:44 EST by Martin Prpič
Modified: 2015-11-16 02:30 EST (History)
2 users (show)

See Also:
Fixed In Version: chromium-browser 45.0.2454.101
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-11-13 05:06:35 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2015-11-11 07:44:36 EST
An unspecified information leak flaw was found in the PDF viewer component of the Chromium browser.

Upstream bug:

https://code.google.com/p/chromium/issues/detail?id=520422

External References:

http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html
Comment 2 Tomas Hoger 2015-11-11 08:35:43 EST
Search using the id of the private upstream bug finds this upstream commit:

https://chromium.googlesource.com/chromium/src/+/a42545fa19dcbdca14c7e53e214b05b3d9356af5
Comment 3 Tomas Hoger 2015-11-13 05:06:35 EST
The above patch is included in the chromium-browser packages as shipped with Red Hat Enterprise Linux 6 Supplementary as of RHSA-2015:1841 updating packages to version 45.0.2454.101.

https://rhn.redhat.com/errata/RHSA-2015-1841.html

Upstream confirmed this issue was not fixed in 46.0.2490.86 for the first time, but was not properly documented in earlier announcements.

Note You need to log in before you can comment on or make changes to this bug.