Ubuntu Security Notice USN-2768-1

Discussion in 'News Aggregator' started by Packet Storm, 19 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2768-1 - Abdulrahman Alqabandi and Ben Kelly discovered that the fetch() API did not correctly implement the Cross Origin Resource Sharing (CORS) specification. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information from other origins.

    Continue reading...
     

Share This Page

Loading...