Bug 1309988 (CVE-2016-1629) - CVE-2016-1629 chromium-browser: same-origin bypass in Blink and Sandbox escape in Chrome
Summary: CVE-2016-1629 chromium-browser: same-origin bypass in Blink and Sandbox escap...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-1629
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1309995 1309996
Blocks: 1309990
TreeView+ depends on / blocked
 
Reported: 2016-02-19 07:21 UTC by Andrej Nemec
Modified: 2021-02-17 04:20 UTC (History)
1 user (show)

Fixed In Version: chromium-browser 48.0.2564.116
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-02-29 04:09:55 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0286 0 normal SHIPPED_LIVE Critical: chromium-browser security update 2016-02-23 12:18:35 UTC

Description Andrej Nemec 2016-02-19 07:21:19 UTC
A critical vulnerability was found in Chrome:

  Critical CVE-2016-1629: Same-origin bypass in Blink and Sandbox escape in
  Chrome. Credit to anonymous.

Upstream bug report:

https://code.google.com/p/chromium/issues/detail?id=583431

External Reference:

http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_18.html

Comment 2 errata-xmlrpc 2016-02-23 07:18:48 UTC
This issue has been addressed in the following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2016:0286 https://rhn.redhat.com/errata/RHSA-2016-0286.html


Note You need to log in before you can comment on or make changes to this bug.