CVE-2015-1298
published 2015-09-03CVE-2015-1298: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.33%
68.2th percentile
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 44.0.2403 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jfr3-3w58-fvcc: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api
ghsa_unreviewed·2022-05-17
CVE-2015-1298 [MEDIUM] GHSA-jfr3-3w58-fvcc: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.
OSV
CVE-2015-1298: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api
osv·2015-09-03·CVSS 4.3
CVE-2015-1298 [MEDIUM] CVE-2015-1298: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.
Red Hat
chromium-browser: URL validation error in extensions
vendor_redhat·2015-09-01·CVSS 4.3
CVE-2015-1298 [MEDIUM] chromium-browser: URL validation error in extensions
chromium-browser: URL validation error in extensions
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1298 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1298 chromium-browser: URL validation error in extensions
bugzilla·2015-09-02·CVSS 4.3
CVE-2015-1298 [MEDIUM] CVE-2015-1298 chromium-browser: URL validation error in extensions
CVE-2015-1298 chromium-browser: URL validation error in extensions
An unspecified url validation error flaw was found in the extensions component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=518827
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1712 https://rhn.redhat.com/errata/RHSA-2015-1712.html
Bugzilla
CVE-2014-1298 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1298 [MEDIUM] CVE-2014-1298 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1298 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1298
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red Hat Product Securi
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=518827https://codereview.chromium.org/1282263002/https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=518827https://codereview.chromium.org/1282263002/https://security.gentoo.org/glsa/201603-09
2015-09-03
Published