Improper access control in Debian Linux and Opensuse - CVE-2016-1668

 

Improper access control in Debian Linux and Opensuse - CVE-2016-1668

Published: May 15, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40287
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1668
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.


Affected software

Debian Linux
Opensuse
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server from RHUI
SUSE Package Hub for SUSE Linux Enterprise
chromium-browser (Red Hat package)
chromium-browser-debuginfo (Red Hat package)

How to mitigate CVE-2016-1668

Install update from vendor's website.

chromium-browser (Red Hat package) - update to 50.0.2661.102-1.el6
chromium-browser-debuginfo (Red Hat package) - update to 50.0.2661.102-1.el6

External References

Related Security Bulletins