CVE-2013-2849

Publication date 22 May 2013

Last updated 24 July 2024


Ubuntu priority

Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
chromium-browser 13.04 raring
Fixed 28.0.1500.52-0ubuntu1.13.04.3
12.10 quantal
Fixed 28.0.1500.52-0ubuntu1.12.10.3
12.04 LTS precise
Fixed 28.0.1500.52-0ubuntu1.12.04.2
10.04 LTS lucid Ignored end of life

References

Other references