Описание
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 33.0.1750.152-0ubuntu1~pkg995.1 |
| lucid | ignored | end of life |
| precise | released | 33.0.1750.152-0ubuntu0.12.04.1~pkg879.1 |
| quantal | released | 33.0.1750.152-0ubuntu0.12.10.1~pkg895.1 |
| saucy | released | 33.0.1750.152-0ubuntu0.13.10.1~pkg984.1 |
| upstream | released | 33.0.1750.146 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| lucid | DNE | |
| precise | DNE | |
| quantal | DNE | |
| saucy | DNE | |
| upstream | needs-triage |
Показывать по
5.8 Medium
CVSS2
Связанные уязвимости
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pe ...
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.
5.8 Medium
CVSS2