Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1706

Опубликовано: 23 июл. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 9.3
CVSS3: 9.6

Описание

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.

РелизСтатусПримечание
devel

released

53.0.2785.143-0ubuntu1.1307
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [52.0.2743.116-0ubuntu0.14.04.1.1134]]
precise

ignored

trusty

released

52.0.2743.116-0ubuntu0.14.04.1.1134
trusty/esm

DNE

trusty was released [52.0.2743.116-0ubuntu0.14.04.1.1134]
upstream

released

52.0.2743.82
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

ignored

end of life
xenial

released

52.0.2743.116-0ubuntu0.16.04.1.1250

Показывать по

РелизСтатусПримечание
devel

released

1.16.7-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.16.5-0ubuntu0.14.04.1]]
esm-infra/xenial

released

1.16.5-0ubuntu0.16.04.1
precise

DNE

trusty

released

1.16.5-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1.16.5-0ubuntu0.14.04.1]
upstream

released

1.16.5
vivid/stable-phone-overlay

released

1.17.9-0ubuntu0.15.04.1~overlay2
vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

9.3 Critical

CVSS2

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
больше 9 лет назад

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.

CVSS3: 9.6
nvd
больше 9 лет назад

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.

CVSS3: 9.6
debian
больше 9 лет назад

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not ...

CVSS3: 9.6
github
больше 3 лет назад

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.

fstec
больше 9 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти защитный механизм песочницы

9.3 Critical

CVSS2

9.6 Critical

CVSS3