CVE-2015-3336

Publication date 19 April 2015

Last updated 24 July 2024


Ubuntu priority

Description

Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by constructing a crafted HTML document containing JavaScript code with requestFullScreen and requestPointerLock calls, and arranging for the user to access this document with a file: URL.

Status

Package Ubuntu Release Status
chromium-browser 15.10 wily
Fixed 43.0.2357.81-0ubuntu1.1179
15.04 vivid
Fixed 43.0.2357.81-0ubuntu0.15.04.1.1170
14.10 utopic
Fixed 43.0.2357.81-0ubuntu0.14.10.1.1131
14.04 LTS trusty
Fixed 43.0.2357.81-0ubuntu0.14.04.1.1089
12.04 LTS precise Ignored
10.04 LTS lucid Ignored end of life
oxide-qt 15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release


Access our resources on patching vulnerabilities