Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902614
Kategorie:General
Titel:Google Chrome Secure Cookie Security Bypass Vulnerability (Windows)
Zusammenfassung:The host is running Google Chrome and is prone to security bypass; vulnerability.
Beschreibung:Summary:
The host is running Google Chrome and is prone to security bypass
vulnerability.

Vulnerability Insight:
The flaw is due to improper restrictions for modifications to cookies
established in HTTPS sessions i.e lack of the HTTP Strict Transport Security
(HSTS) includeSubDomains feature, which allows man-in-the-middle attackers
to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP
response.

Vulnerability Impact:
Successful exploitation will allow attackers to overwrite or delete arbitrary
cookies by sending a specially crafted HTTP response through a man-in-the-
middle attack.

Affected Software/OS:
Google Chrome version prior to 4.0.211.0 on Windows.

Solution:
Upgrade to the Google Chrome 4.0.211.0 or later.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Querverweis: BugTraq ID: 49133
Common Vulnerability Exposure (CVE) ID: CVE-2008-7294
http://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy_for_cookies
http://michael-coates.blogspot.com/2010/01/cookie-forcing-trust-your-cookies-no.html
http://scarybeastsecurity.blogspot.com/2008/11/cookie-forcing.html
http://scarybeastsecurity.blogspot.com/2011/02/some-less-obvious-benefits-of-hsts.html
https://bugzilla.mozilla.org/show_bug.cgi?id=660053
http://lists.w3.org/Archives/Public/public-webapps/2009JulSep/1148.html
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.