CVE-2016-1627
published 2016-02-14CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.32%
67.4th percentile
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 48.0.2564.103 | — | |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9v85-hq57-2c7g: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48
ghsa_unreviewed·2022-05-14
CVE-2016-1627 [HIGH] GHSA-9v85-hq57-2c7g: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.
OSV
CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48
osv·2016-02-14·CVSS 8.8
CVE-2016-1627 [HIGH] CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-1627 [HIGH] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
bugzilla·2016-04-12·CVSS 6.5
CVE-2016-3658 [MEDIUM] CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
A vulnerability was found in the libtiff library. Using a tiffset command on a maliciously crafted image could result in a denial-of-service.
Vulnerable code:
/libtiff/tif_dirwrite.c: 1625
1623 for (q=p, ma=value, mb=0; mb0xFFFFFFFF)
1626 {
1627 TIFFErrorExt(tif->tif_clientdata,module,
1628 "Attempt to write value larger than 0xFFFFFFFF in Classic TIFF file.");
1629 _TIFFfree(p);
1630 return(0);
1631 }
1632 *q= (uint32)(*ma);
1633 }
References:
http://www.openwall.com/lists/oss-security/2016/04/08/12
Discussion:
External References:
http://bugzilla.maptools.org/show_bug.cgi?id=2546
---
*** This bug has been marked as a duplicate of bug 1185805 ***
---
Statement:
This flaw was found to
Bugzilla
CVE-2016-1627 chromium-browser: various fixes from internal audits
bugzilla·2016-02-10·CVSS 8.8
CVE-2016-1627 [HIGH] CVE-2016-1627 chromium-browser: various fixes from internal audits
CVE-2016-1627 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=585517
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183https://code.google.com/p/chromium/issues/detail?id=571121https://code.google.com/p/chromium/issues/detail?id=585517https://codereview.chromium.org/1586903002https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183https://code.google.com/p/chromium/issues/detail?id=571121https://code.google.com/p/chromium/issues/detail?id=585517https://codereview.chromium.org/1586903002https://security.gentoo.org/glsa/201603-09
2016-02-14
Published