CVE-2016-1658

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:novell:suse_package_hub_for_suse_linux_enterprise:12:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:30

Type Values Removed Values Added
References (CONFIRM) https://codereview.chromium.org/1658913002 - () https://codereview.chromium.org/1658913002 -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html - Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html -
References (DEBIAN) http://www.debian.org/security/2016/dsa-3549 - Third Party Advisory () http://www.debian.org/security/2016/dsa-3549 -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html - Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html -
References (CONFIRM) https://crbug.com/573317 - () https://crbug.com/573317 -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2016-0638.html - () http://rhn.redhat.com/errata/RHSA-2016-0638.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html -
References (GENTOO) https://security.gentoo.org/glsa/201605-02 - () https://security.gentoo.org/glsa/201605-02 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html -

Information

Published : 2016-04-18 10:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-1658

Mitre link : CVE-2016-1658

CVE.ORG link : CVE-2016-1658


JSON object : View

Products Affected

novell

  • suse_package_hub_for_suse_linux_enterprise

opensuse

  • leap

google

  • chrome

debian

  • debian_linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control