Oval Definition:oval:com.ubuntu.precise:def:20156785000
Revision Date:2015-12-05Version:1
Title:CVE-2015-6785 on Ubuntu 12.04 LTS (precise) - medium.
Description:The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a policy that was intended to be specific to subdomains.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-6785
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, a decision has been made to ignore it.
  • BACK