Bug 1280298 (CVE-2015-1302) - CVE-2015-1302 chromium-browser: information leak in PDF viewer
Summary: CVE-2015-1302 chromium-browser: information leak in PDF viewer
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-1302
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1266411 1266412 1280305 1280306
Blocks: 1280299
TreeView+ depends on / blocked
 
Reported: 2015-11-11 12:44 UTC by Martin Prpič
Modified: 2021-02-17 04:43 UTC (History)
2 users (show)

Fixed In Version: chromium-browser 45.0.2454.101
Clone Of:
Environment:
Last Closed: 2015-11-13 10:06:35 UTC
Embargoed:


Attachments (Terms of Use)

Description Martin Prpič 2015-11-11 12:44:36 UTC
An unspecified information leak flaw was found in the PDF viewer component of the Chromium browser.

Upstream bug:

https://code.google.com/p/chromium/issues/detail?id=520422

External References:

http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html

Comment 2 Tomas Hoger 2015-11-11 13:35:43 UTC
Search using the id of the private upstream bug finds this upstream commit:

https://chromium.googlesource.com/chromium/src/+/a42545fa19dcbdca14c7e53e214b05b3d9356af5

Comment 3 Tomas Hoger 2015-11-13 10:06:35 UTC
The above patch is included in the chromium-browser packages as shipped with Red Hat Enterprise Linux 6 Supplementary as of RHSA-2015:1841 updating packages to version 45.0.2454.101.

https://rhn.redhat.com/errata/RHSA-2015-1841.html

Upstream confirmed this issue was not fixed in 46.0.2490.86 for the first time, but was not properly documented in earlier announcements.


Note You need to log in before you can comment on or make changes to this bug.