PT-2009-4524 · Google · Google Chrome

Adam Barth

+1

·

Published

2009-06-15

·

Updated

2009-06-23

·

CVE-2009-2071

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 1.0.154.53
Description The issue allows man-in-the-middle attackers to spoof an arbitrary https site. This is done by letting a browser obtain a valid certificate from the site during one request and then sending the browser a crafted 502 response page upon a subsequent request. The problem occurs when Google Chrome displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server.
Recommendations For Google Chrome versions prior to 1.0.154.53, update to version 1.0.154.53 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2071

Affected Products

Google Chrome