CVE-2015-1285

Severity
5.0MEDIUM
EPSS
1.1%
top 21.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

NVDgoogle/chrome43.0.2357.134
Ubuntuoxide-qt< 1.8.4-0ubuntu0.14.04.2
Ubuntuchromium-browser< 44.0.2403.89-0ubuntu0.14.04.1.1095
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

3
GHSA
GHSA-86pj-mwrp-p73h: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor2022-05-14
CVEList
CVE-2015-1285: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor2015-07-23
OSV
CVE-2015-1285: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor2015-07-22

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-08-04
Red Hat
chromium-browser: Information leak in XSS auditor.2015-07-21

💬Community

1
Bugzilla
CVE-2015-1285 chromium-browser: Information leak in XSS auditor.2015-07-22
CVE-2015-1285 (MEDIUM CVSS 5) | The XSSAuditor::canonicalize functi | cvebase.io