{"id":"MGASA-2015-0448","summary":"Updated chromium-browser-stable packages fix security vulnerabilities","details":"Updated chromium-browser-stable packages fix security vulnerabilities:\n\nThe PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict\nscripting messages and API exposure, which allows remote attackers to bypass\nthe Same Origin Policy via an unintended embedder or unintended plugin loading,\nrelated to pdf.js and out_of_process_instance.cc (CVE-2015-1302).\n","modified":"2026-04-16T06:25:18.040120190Z","published":"2015-11-16T21:36:58Z","upstream":["CVE-2015-1302"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0448.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17125"},{"type":"WEB","url":"http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html"}],"affected":[{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"46.0.2490.86-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0448.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}