Vulnerability Name: | CVE-2015-6783 (CCN-108421) | ||||||||||||||||||||||||
Assigned: | 2015-12-01 | ||||||||||||||||||||||||
Published: | 2015-12-01 | ||||||||||||||||||||||||
Updated: | 2017-09-14 | ||||||||||||||||||||||||
Summary: | The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-6783 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:2290 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:2291 Source: BID Type: UNKNOWN 78416 Source: CCN Type: BID-78416 Google Chrome Prior to 47.0.2526.73 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1034298 Source: CONFIRM Type: UNKNOWN https://chromium.googlesource.com/chromium/src.git/+/d9e316238aee59acf665d80b544cf4e1edfd3349 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=537205 Source: XF Type: UNKNOWN google-chrome-cve20156783-sec-bypass(108421) Source: GENTOO Type: UNKNOWN GLSA-201603-09 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |