Permissions, Privileges, and Access Controls in Debian Linux and Opensuse - CVE-2016-1622
Published: February 14, 2016 / Updated: August 9, 2020
SUSE
Debian Linux
Opensuse
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
How to mitigate CVE-2016-1622
Sources
- http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html
- http://rhn.redhat.com/errata/RHSA-2016-0241.html
- http://www.debian.org/security/2016/dsa-3486
- http://www.securityfocus.com/bid/83125
- http://www.securitytracker.com/id/1035183
- https://code.google.com/p/chromium/issues/detail?id=546677
- https://codereview.chromium.org/1417513003
- https://security.gentoo.org/glsa/201603-09