CVE-2015-2239
Published: 9 March 2015
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.
Notes
Author | Note |
---|---|
chrisccouson | Looks like this is a browser bug |
Priority
Status
Package | Release | Status |
---|---|---|
chromium-browser Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Ignored
|
|
trusty |
Released
(41.0.2272.76-0ubuntu0.14.04.1.1076)
|
|
upstream |
Released
(41.0.2272.76)
|
|
utopic |
Released
(41.0.2272.76-0ubuntu0.14.10.1.1118)
|
|
vivid |
Released
(41.0.2272.76-0ubuntu1.1134)
|
|
wily |
Released
(41.0.2272.76-0ubuntu1.1134)
|
|
oxide-qt Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|
|
wily |
Not vulnerable
|