PT-2017-3894 · Google+3 · Google Chrome+3
Publicado
2017-08-31
·
Atualizado
2024-06-15
·
CVE-2019-13715
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 78.0.3904.70
Description
The issue is related to insufficient validation of untrusted input in the Omnibox component of Google Chrome, allowing a remote attacker to perform domain spoofing via IDN homographs using a crafted domain name. This can be exploited by a remote attacker to conduct spoofing attacks with a specially crafted domain name.
Recommendations
For versions prior to 78.0.3904.70, update to version 78.0.3904.70 or later to resolve the issue.
Correção
Authentication Bypass by Spoofing
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Red Hat
Suse