CVE-2015-1261

MEDIUM

Description

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

References

http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html

http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html

http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html

http://www.debian.org/security/2015/dsa-3267

http://www.securityfocus.com/bid/74723

http://www.securitytracker.com/id/1032375

https://code.google.com/p/chromium/issues/detail?id=466351

https://codereview.chromium.org/1011383005

https://codereview.chromium.org/1056743002

https://codereview.chromium.org/1077483002

Details

Source: MITRE

Published: 2015-05-20

Updated: 2017-01-03

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM