CVE-2016-1706
published 2016-07-23CVE-2016-1706: The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come…
PriorityP341critical9.6CVSS 3.0
AVNACLPRNUIRSCCHIHAH
EPSS
2.46%
82.8th percentile
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 51.0.2704.106 | — |
CVSS provenance
nvdv3.09.6CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.6CRITICAL
vendor_redhat9.6CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4c3c-m7vg-64hg: The PPAPI implementation in Google Chrome before 52
ghsa_unreviewed·2022-05-17
CVE-2016-1706 [CRITICAL] CWE-20 GHSA-4c3c-m7vg-64hg: The PPAPI implementation in Google Chrome before 52
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
OSV
oxide-qt vulnerabilities
osv·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovered that Blink does not disable frame navigation during a
det
OSV
CVE-2016-1706: The PPAPI implementation in Google Chrome before 52
osv·2016-07-23·CVSS 9.6
CVE-2016-1706 [CRITICAL] CVE-2016-1706: The PPAPI implementation in Google Chrome before 52
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovere
Red Hat
chromium-browser: sandbox escape in ppapi
vendor_redhat·2016-07-20·CVSS 9.6
CVE-2016-1706 [CRITICAL] chromium-browser: sandbox escape in ppapi
chromium-browser: sandbox escape in ppapi
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1706 chromium-browser: sandbox escape in ppapi
bugzilla·2016-07-21·CVSS 9.6
CVE-2016-1706 [CRITICAL] CVE-2016-1706 chromium-browser: sandbox escape in ppapi
CVE-2016-1706 chromium-browser: sandbox escape in ppapi
A sandbox escape flaw was found in the PPAPI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=610600
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1485 https://rhn.redhat.com/errata/RHSA-2016-1485.html
Bugzilla
python-pillow: Buffer overflow in PcdDecode.c
bugzilla·2016-02-05
[MEDIUM] python-pillow: Buffer overflow in PcdDecode.c
python-pillow: Buffer overflow in PcdDecode.c
A buffer overflow vulnerability was found in PcdDecode.c, where PCD decoder overruns shuffle buffer by writing 4 bytes into 3 byte per pixel wide buffer, allowing to write 768 bytes off the end of the buffer. This overwrites objects in Python's stack, leading to a crash.
Upstream bug report:
https://github.com/python-pillow/Pillow/pull/1706
CVE request:
http://openwall.com/lists/oss-security/2016/02/02/5
Discussion:
Created python-pillow tracking bugs for this issue:
Affects: fedora-all [bug 1305005]
---
*** This bug has been marked as a duplicate of bug 1304504 ***
---
python-pillow-3.0.0-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
---
python-pil
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2069853002/https://crbug.com/610600http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2069853002/https://crbug.com/610600
2016-07-23
Published