PT-2014-1375 · Google+2 · Google Chrome+2

Rob Wu

·

Publicado

2014-08-26

·

Atualizado

2024-06-15

·

CVE-2014-3170

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 37.0.2062.94
Description The issue exists due to the possibility of using the '0' character in host names, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character. This can be exploited by attackers to manipulate the dialog, potentially leading to unauthorized access or actions.
Recommendations For Google Chrome versions prior to 37.0.2062.94, update to version 37.0.2062.94 or later to resolve the issue. As a temporary workaround, consider restricting the use of extensions that rely on host names to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2044
BDU:2015-00237
CVE-2014-3170
DSA-3039-1
OPENSUSE-SU-2014_1151-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1

Produtos afetados

Alt Linux
Google Chrome
Suse