Hide Forgot
It was found that v8, a Google's open source JavaScript engine, did not properly enforce same origin policy when loading certain URLs. A remote attacker using web browser utilizing the service of v8 engine could use this flaw to load or set properties of a document from another origin. References: [1] http://bugs.gentoo.org/show_bug.cgi?id=370627 [2] http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.html
This issue affects the version of the v8 package, as shipped with Fedora release of 15. Please schedule an update.
Created v8 tracking bugs for this issue Affects: fedora-15 [bug 711732]
This has been fixed long ago in Fedora (this was fixed in Chrome 12): * Fri Jul 06 2012 Tom Callaway <spot@xxx> 1:3.10.8-1 - update to 3.10.8 (chromium 20)