CVE-2015-1297
published 2015-09-03CVE-2015-1297: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.24%
81.1th percentile
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 44.0.2403 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Permission scoping error in WebRequest
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1297 [HIGH] chromium-browser: Permission scoping error in WebRequest
chromium-browser: Permission scoping error in WebRequest
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.
Red Hat
webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2014-1297 [MEDIUM] webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-mc69-hgc6-9g2h: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api
ghsa_unreviewed·2022-05-17
CVE-2015-1297 [HIGH] GHSA-mc69-hgc6-9g2h: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.
OSV
CVE-2015-1297: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api
osv·2015-09-03·CVSS 7.5
CVE-2015-1297 [HIGH] CVE-2015-1297: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1297 chromium-browser: Permission scoping error in WebRequest
bugzilla·2015-09-02·CVSS 7.5
CVE-2015-1297 [HIGH] CVE-2015-1297 chromium-browser: Permission scoping error in WebRequest
CVE-2015-1297 chromium-browser: Permission scoping error in WebRequest
An unspecified permission scoping error flaw was found in the WebRequest component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=510802
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1712 https://rhn.redhat.com/errata/RHSA-2015-1712.html
Bugzilla
CVE-2014-1297 webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 5.0
CVE-2014-1297 [MEDIUM] CVE-2014-1297 webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
CVE-2014-1297 webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1297
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue i
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=510802https://codereview.chromium.org/1267183003/https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=510802https://codereview.chromium.org/1267183003/https://security.gentoo.org/glsa/201603-09
2015-09-03
Published