PT-2015-1199 · Opera+4 · Opera+4

Publicado

2015-05-19

·

Atualizado

2024-06-15

·

CVE-2015-1260

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 43.0.2357.65 Opera versions prior to 43.0.2357.65
Description The issue is caused by multiple use-after-free vulnerabilities in the content/renderer/media/user media client impl.cc file in the WebRTC implementation. This allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that executes upon completion of a getUserMedia request.
Recommendations For Google Chrome versions prior to 43.0.2357.65, update to version 43.0.2357.65 or later. For Opera versions prior to 43.0.2357.65, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the getUserMedia request until a patch is available. Restrict access to the WebRTC implementation to minimize the risk of exploitation.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1589
BDU:2015-10133
CVE-2015-1260
DSA-3267-1
MGASA-2015-0235
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2015:1023
RHSA-2015_1023
USN-2610-1

Produtos afetados

Alt Linux
Google Chrome
Opera
Red Hat
Ubuntu