PT-2009-4524 · Google · Google Chrome
Adam Barth
+1
·
Published
2009-06-15
·
Updated
2009-06-23
·
CVE-2009-2071
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 1.0.154.53
Description
The issue allows man-in-the-middle attackers to spoof an arbitrary https site. This is done by letting a browser obtain a valid certificate from the site during one request and then sending the browser a crafted 502 response page upon a subsequent request. The problem occurs when Google Chrome displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server.
Recommendations
For Google Chrome versions prior to 1.0.154.53, update to version 1.0.154.53 or later to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome