Permissions, Privileges, and Access Controls in Opensuse and Debian Linux - CVE-2016-1627

 

Permissions, Privileges, and Access Controls in Opensuse and Debian Linux - CVE-2016-1627

Published: February 14, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40482
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-1627
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: SUSE
Debian
Affected software:
Opensuse
Debian Linux

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.


How to mitigate CVE-2016-1627

Install update from vendor's website.

Sources