CVE-2011-2332
published 2011-06-09CVE-2011-2332: Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.39%
69.7th percentile
Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 12.0.742.91 | 12.0.742.91 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2332 v8: Same origin bypass
bugzilla·2011-06-08·CVSS 7.5
CVE-2011-2332 [HIGH] CVE-2011-2332 v8: Same origin bypass
CVE-2011-2332 v8: Same origin bypass
It was found that v8, a Google's open source JavaScript engine, did not
properly enforce same origin policy when loading certain URLs. A remote
attacker using web browser utilizing the service of v8 engine could use
this flaw to load or set properties of a document from another origin.
References:
[1] http://bugs.gentoo.org/show_bug.cgi?id=370627
[2] http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.html
Discussion:
This issue affects the version of the v8 package, as shipped with
Fedora release of 15. Please schedule an update.
---
Created v8 tracking bugs for this issue
Affects: fedora-15 [bug 711732]
---
This has been fixed long ago in Fedora (this was fixed in Chrome 12):
* Fri Jul 06 2012 Tom Callaway 1:3.10.8-1
- upd
Bugzilla
CVE-2011-2332 v8: Same origin bypass [fedora-15]
bugzilla·2011-06-08·CVSS 7.5
CVE-2011-2332 [HIGH] CVE-2011-2332 v8: Same origin bypass [fedora-15]
CVE-2011-2332 v8: Same origin bypass [fedora-15]
fedora-15 tracking bug for v8: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Bumping the release; I don't know if this is fixed in F16 or not, but we do have v8 there and I don't want this closed when F15 is EOL.
---
This message is a reminder that Fedora 16 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 16. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'versi
http://code.google.com/p/chromium/issues/detail?id=83275http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.htmlhttp://osvdb.org/72790http://secunia.com/advisories/44829http://www.securityfocus.com/bid/48129https://exchange.xforce.ibmcloud.com/vulnerabilities/67903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14242http://code.google.com/p/chromium/issues/detail?id=83275http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.htmlhttp://osvdb.org/72790http://secunia.com/advisories/44829http://www.securityfocus.com/bid/48129https://exchange.xforce.ibmcloud.com/vulnerabilities/67903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14242
2011-06-09
Published