UBUNTU-CVE-2015-1241
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-1241
UBUNTU-CVE-2015-1241
Summary:
Details: Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
References: https://ubuntu.com/security/CVE-2015-1241, https://codereview.chromium.org/868123002, https://codereview.chromium.org/717573004, https://codereview.chromium.org/660663002, https://codereview.chromium.org/628763003, https://code.google.com/p/chromium/issues/detail?id=418402, http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html, https://ubuntu.com/security/notices/USN-2570-1, https://www.cve.org/CVERecord?id=CVE-2015-1241
Affected packages
Package
Name: chromium-browser
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
