UBUNTU-CVE-2015-6790
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-6790
UBUNTU-CVE-2015-6790
Summary:
Details: The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-quoted string.
References: https://ubuntu.com/security/CVE-2015-6790, http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_8.html, https://ubuntu.com/security/notices/USN-2860-1, https://www.cve.org/CVERecord?id=CVE-2015-6790
Affected packages
Package
Name: chromium-browser
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
