Race condition in Debian Linux and Opensuse - CVE-2016-1670
Published: May 15, 2016 / Updated: August 9, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a renderer process and reusing a request ID.
Affected software
Opensuse
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server from RHUI
SUSE Package Hub for SUSE Linux Enterprise
chromium-browser (Red Hat package)
chromium-browser-debuginfo (Red Hat package)
How to mitigate CVE-2016-1670
chromium-browser-debuginfo (Red Hat package) - update to 50.0.2661.102-1.el6
External References
- http://googlechromereleases.blogspot.com/2016/05/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00048.html
- http://rhn.redhat.com/errata/RHSA-2016-1080.html
- http://www.debian.org/security/2016/dsa-3590
- http://www.securityfocus.com/bid/90584
- http://www.securitytracker.com/id/1035872
- http://www.ubuntu.com/usn/USN-2960-1
- https://codereview.chromium.org/1608573002
- https://crbug.com/578882
- https://security.gentoo.org/glsa/201605-02