CVE-2016-2785
published 2016-06-10CVE-2016-2785: Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.89%
85.4th percentile
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| debian | puppetserver | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 4.0.0 < 4.4.2 | 4.4.2 |
| puppet | puppet_agent | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
| puppet | puppet_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Puppet Improper Access Control
osv·2022-05-13
CVE-2016-2785 [CRITICAL] Puppet Improper Access Control
Puppet Improper Access Control
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
GHSA
Puppet Improper Access Control
ghsa·2022-05-13
CVE-2016-2785 [CRITICAL] CWE-284 Puppet Improper Access Control
Puppet Improper Access Control
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2016-09-29·CVSS 9.8
CVE-2016-5178 [CRITICAL] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
chromium-browser: SafeBrowsing protection mechanism bypass
vendor_redhat·2016-09-29·CVSS 6.5
CVE-2016-5176 [MEDIUM] chromium-browser: SafeBrowsing protection mechanism bypass
chromium-browser: SafeBrowsing protection mechanism bypass
Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
Red Hat
chromium-browser: use after free in blink
vendor_redhat·2016-09-13·CVSS 8.8
CVE-2016-5170 [HIGH] chromium-browser: use after free in blink
chromium-browser: use after free in blink
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Indexed Database (aka IndexedDB) API calls.
Red Hat
chromium-browser: use after free in blink
vendor_redhat·2016-09-13·CVSS 8.8
CVE-2016-5171 [HIGH] chromium-browser: use after free in blink
chromium-browser: use after free in blink
WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
Red Hat
chromium-browser: arbitrary memory read in v8
vendor_redhat·2016-09-13·CVSS 6.5
CVE-2016-5172 [MEDIUM] chromium-browser: arbitrary memory read in v8
chromium-browser: arbitrary memory read in v8
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2016-09-13·CVSS 8.8
CVE-2016-5175 [HIGH] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
chromium-browser: extension resource access
vendor_redhat·2016-09-13·CVSS 7.1
CVE-2016-5173 [HIGH] chromium-browser: extension resource access
chromium-browser: extension resource access
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
Red Hat
chromium-browser: heap overflow in pdfium
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5157 [HIGH] chromium-browser: heap overflow in pdfium
chromium-browser: heap overflow in pdfium
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Red Hat
chromium-browser: address bar spoofing
vendor_redhat·2016-08-31·CVSS 4.3
CVE-2016-5163 [MEDIUM] chromium-browser: address bar spoofing
chromium-browser: address bar spoofing
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted right-to-left (RTL) Unicode text, related to omnibox/SuggestionView.java and omnibox/UrlBar.java in Chrome for Android.
Red Hat
chromium-browser: type confusion in blink
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5161 [HIGH] chromium-browser: type confusion in blink
chromium-browser: type confusion in blink
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that leverages "type confusion" in the StylePropertySerializer class.
Red Hat
chromium-browser: extensions web accessible resources bypass
vendor_redhat·2016-08-31·CVSS 6.5
CVE-2016-5162 [MEDIUM] chromium-browser: extensions web accessible resources bypass
chromium-browser: extensions web accessible resources bypass
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources field for restrictions on IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks, and trick users into changing extension settings, via a crafted web site, a different vulnerability than CVE-2016-5160.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5151 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/javascript/JS_Object.cpp and fpdfsdk/javascript/app.cpp.
Red Hat
chromium-browser: universal xss using devtools
vendor_redhat·2016-08-31·CVSS 6.1
CVE-2016-5164 [MEDIUM] chromium-browser: universal xss using devtools
chromium-browser: universal xss using devtools
Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML into the Developer Tools (aka DevTools) subsystem via a crafted web site, aka "Universal XSS (UXSS)."
Red Hat
chromium-browser: use after destruction in blink
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5153 [HIGH] chromium-browser: use after destruction in blink
chromium-browser: use after destruction in blink
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destruction) or possibly have unspecified other impact via a crafted web site.
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2016-08-31·CVSS 6.1
CVE-2016-5148 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)."
Red Hat
chromium-browser: address bar spoofing
vendor_redhat·2016-08-31·CVSS 6.5
CVE-2016-5155 [MEDIUM] chromium-browser: address bar spoofing
chromium-browser: address bar spoofing
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.
Red Hat
chromium-browser: heap overflow in pdfium
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5152 [HIGH] chromium-browser: heap overflow in pdfium
chromium-browser: heap overflow in pdfium
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
Package: openjpeg (Red Hat Enterprise Linux 5) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Red Hat
chromium-browser: use after free in blink
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5150 [HIGH] chromium-browser: use after free in blink
chromium-browser: use after free in blink
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects.
Red Hat
chromium-browser: script injection in devtools
vendor_redhat·2016-08-31·CVSS 6.1
CVE-2016-5165 [MEDIUM] chromium-browser: script injection in devtools
chromium-browser: script injection in devtools
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the settings parameter in a chrome-devtools-frontend.appspot.com URL's query string.
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5167 [HIGH] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
puppet: incorrect URL decoding
vendor_redhat·2016-04-26·CVSS 9.8
CVE-2016-2785 [CRITICAL] puppet: incorrect URL decoding
puppet: incorrect URL decoding
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
Statement: This issue did not affect the versions of Puppet as shipped with various Red Hat products as they did not include support Puppet 3.x (using Passenger 4.x).
Package: puppet (OpenStack Foreman) - Will not fix
Package: puppet (Red Hat Ceph Storage 1.3) - Not affected
Package: puppet (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: puppet (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Will not fix
Package: puppet (Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer) - Wi
Debian
CVE-2016-2785: puppet - Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and ...
vendor_debian·2016·CVSS 9.8
CVE-2016-2785 [CRITICAL] CVE-2016-2785: puppet - Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and ...
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5176 chromium-browser: SafeBrowsing protection mechanism bypass
bugzilla·2016-09-29·CVSS 6.5
CVE-2016-5176 [MEDIUM] CVE-2016-5176 chromium-browser: SafeBrowsing protection mechanism bypass
CVE-2016-5176 chromium-browser: SafeBrowsing protection mechanism bypass
Google Chrome before 53.0.2785.113 allows remote attackers to bypass
the SafeBrowsing protection mechanism via unspecified vectors.
Upstream bug:
https://bugs.chromium.org/p/chromium/issues/detail?id=595838
External References:
https://googlechromereleases.blogspot.cz/2016/09/stable-channel-update-for-desktop_13.html
Bugzilla
CVE-2016-5175 chromium-browser: various fixes from internal audits
bugzilla·2016-09-14·CVSS 8.8
CVE-2016-5175 [HIGH] CVE-2016-5175 chromium-browser: various fixes from internal audits
CVE-2016-5175 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=646394
External References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1375871]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1905 https://rhn.redhat.com/errata/RHSA-2016-1905.html
---
chromium-53.0.2785.113-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2016-5173 chromium-browser: extension resource access
bugzilla·2016-09-14·CVSS 7.1
CVE-2016-5173 [HIGH] CVE-2016-5173 chromium-browser: extension resource access
CVE-2016-5173 chromium-browser: extension resource access
The following flaw was identified in the Chromium browser: extension resource access.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=468931
External References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1375871]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1905 https://rhn.redhat.com/errata/RHSA-2016-1905.html
---
chromium-53.0.2785.113-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2016-5174 chromium-browser: popup not correctly suppressed
bugzilla·2016-09-14·CVSS 6.5
CVE-2016-5174 [MEDIUM] CVE-2016-5174 chromium-browser: popup not correctly suppressed
CVE-2016-5174 chromium-browser: popup not correctly suppressed
The following flaw was identified in the Chromium browser: popup not correctly suppressed.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=579934
External References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1375871]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1905 https://rhn.redhat.com/errata/RHSA-2016-1905.html
---
chromium-53.0.2785.113-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2016-5170 chromium-browser: use after free in blink
bugzilla·2016-09-14·CVSS 8.8
CVE-2016-5170 [HIGH] CVE-2016-5170 chromium-browser: use after free in blink
CVE-2016-5170 chromium-browser: use after free in blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=641101
External References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1375871]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1905 https://rhn.redhat.com/errata/RHSA-2016-1905.html
---
chromium-53.0.2785.113-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2016-5155 chromium-browser: address bar spoofing
bugzilla·2016-09-01·CVSS 6.5
CVE-2016-5155 [MEDIUM] CVE-2016-5155 chromium-browser: address bar spoofing
CVE-2016-5155 chromium-browser: address bar spoofing
The following flaw was identified in the Chromium browser: address bar spoofing.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=630662
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has bee
Bugzilla
CVE-2016-5161 chromium-browser: type confusion in blink
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5161 [HIGH] CVE-2016-5161 chromium-browser: type confusion in blink
CVE-2016-5161 chromium-browser: type confusion in blink
A type confusion flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=622420
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has b
Bugzilla
CVE-2016-5165 chromium-browser: script injection in devtools
bugzilla·2016-09-01·CVSS 6.1
CVE-2016-5165 [MEDIUM] CVE-2016-5165 chromium-browser: script injection in devtools
CVE-2016-5165 chromium-browser: script injection in devtools
A script injection flaw was found in the DevTools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=618037
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.
Bugzilla
CVE-2016-5159 chromium-browser, openjpeg: heap overflow in parsing of JPEG2000 code blocks
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5159 [HIGH] CVE-2016-5159 chromium-browser, openjpeg: heap overflow in parsing of JPEG2000 code blocks
CVE-2016-5159 chromium-browser, openjpeg: heap overflow in parsing of JPEG2000 code blocks
A heap overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=628304
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
Bugzilla
CVE-2016-5149 chromium-browser: script injection in extensions
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5149 [HIGH] CVE-2016-5149 chromium-browser: script injection in extensions
CVE-2016-5149 chromium-browser: script injection in extensions
A script injection flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=573131
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.10
Bugzilla
CVE-2016-5150 chromium-browser: use after free in blink
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5150 [HIGH] CVE-2016-5150 chromium-browser: use after free in blink
CVE-2016-5150 chromium-browser: use after free in blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=637963
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has
Bugzilla
CVE-2016-5147 chromium-browser: universal xss in blink
bugzilla·2016-09-01·CVSS 6.1
CVE-2016-5147 [MEDIUM] CVE-2016-5147 chromium-browser: universal xss in blink
CVE-2016-5147 chromium-browser: universal xss in blink
An universal xss flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=628942
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has be
Bugzilla
CVE-2016-5166 chromium-browser: smb relay attack via save page as
bugzilla·2016-09-01·CVSS 3.1
CVE-2016-5166 [LOW] CVE-2016-5166 chromium-browser: smb relay attack via save page as
CVE-2016-5166 chromium-browser: smb relay attack via save page as
The following flaw was identified in the Chromium browser: smb relay attack via save page as.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=616429
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53
Bugzilla
CVE-2016-5164 chromium-browser: universal xss using devtools
bugzilla·2016-09-01·CVSS 6.1
CVE-2016-5164 [MEDIUM] CVE-2016-5164 chromium-browser: universal xss using devtools
CVE-2016-5164 chromium-browser: universal xss using devtools
The following flaw was identified in the Chromium browser: universal xss using devtools.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=637594
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.10
Bugzilla
CVE-2016-5154 chromium-browser: heap overflow in pdfium
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5154 [HIGH] CVE-2016-5154 chromium-browser: heap overflow in pdfium
CVE-2016-5154 chromium-browser: heap overflow in pdfium
A heap overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=633002
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has b
Bugzilla
CVE-2016-5157 chromium-browser: heap overflow in pdfium
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5157 [HIGH] CVE-2016-5157 chromium-browser: heap overflow in pdfium
CVE-2016-5157 chromium-browser: heap overflow in pdfium
A heap overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=632622
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has b
Bugzilla
CVE-2016-5156 chromium-browser: use after free in event bindings
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5156 [HIGH] CVE-2016-5156 chromium-browser: use after free in event bindings
CVE-2016-5156 chromium-browser: use after free in event bindings
An use after free flaw was found in the event bindings component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=625404
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.27
Bugzilla
CVE-2016-5163 chromium-browser: address bar spoofing
bugzilla·2016-09-01·CVSS 4.3
CVE-2016-5163 [MEDIUM] CVE-2016-5163 chromium-browser: address bar spoofing
CVE-2016-5163 chromium-browser: address bar spoofing
The following flaw was identified in the Chromium browser: address bar spoofing.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=609680
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has bee
Bugzilla
CVE-2016-5153 chromium-browser: use after destruction in blink
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5153 [HIGH] CVE-2016-5153 chromium-browser: use after destruction in blink
CVE-2016-5153 chromium-browser: use after destruction in blink
An use after destruction flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=631052
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.1
Bugzilla
CVE-2016-5151 chromium-browser: use after free in pdfium
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5151 [HIGH] CVE-2016-5151 chromium-browser: use after free in pdfium
CVE-2016-5151 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=634716
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 ha
Bugzilla
CVE-2016-2785 puppet: incorrect URL decoding
bugzilla·2016-04-27·CVSS 9.8
CVE-2016-2785 [CRITICAL] CVE-2016-2785 puppet: incorrect URL decoding
CVE-2016-2785 puppet: incorrect URL decoding
The following flaw was found in Puppet:
Puppet Server 2.x and Ruby Puppet Master from Puppet 4.x did not correctly decode specific character combinations which could potentially allow for a host to access endpoints restricted by auth.conf rules.
This issue is fixed in Puppet Server 2.3.2, Puppet 4.4.2, and Puppet Agent 1.4.2.
External References:
https://puppet.com/security/cve/cve-2016-2785
Discussion:
Created puppet tracking bugs for this issue:
Affects: fedora-all [bug 1331025]
Affects: epel-all [bug 1331026]
---
Statement:
This issue did not affect the versions of Puppet as shipped with various Red Hat products as they did not include support Puppet 3.x (using Passenger 4.x).
Bugzilla
CVE-2016-2785 puppet: incorrect URL decoding [fedora-all]
bugzilla·2016-04-27·CVSS 9.8
CVE-2016-2785 [CRITICAL] CVE-2016-2785 puppet: incorrect URL decoding [fedora-all]
CVE-2016-2785 puppet: incorrect URL decoding [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
o
Bugzilla
CVE-2016-2785 puppet: incorrect URL decoding [epel-all]
bugzilla·2016-04-27·CVSS 9.8
CVE-2016-2785 [CRITICAL] CVE-2016-2785 puppet: incorrect URL decoding [epel-all]
CVE-2016-2785 puppet: incorrect URL decoding [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. Whil
https://github.com/puppetlabs/puppet/pull/4921/commits/8d2ce797db265720f0a20d1d46ee2757b4e4f6b2https://puppet.com/security/cve/cve-2016-2785https://security.gentoo.org/glsa/201606-02https://github.com/puppetlabs/puppet/pull/4921/commits/8d2ce797db265720f0a20d1d46ee2757b4e4f6b2https://puppet.com/security/cve/cve-2016-2785https://security.gentoo.org/glsa/201606-02
2016-06-10
Published