CVE-2015-1295

HIGH

Description

Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.

References

http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html

http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html

http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html

http://rhn.redhat.com/errata/RHSA-2015-1712.html

http://www.debian.org/security/2015/dsa-3351

http://www.securitytracker.com/id/1033472

https://code.google.com/p/chromium/issues/detail?id=502562

https://codereview.chromium.org/1228693002/

https://security.gentoo.org/glsa/201603-09

Details

Source: MITRE

Published: 2015-09-03

Updated: 2016-12-22

Risk Information

CVSS v2.0

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH