Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
BID:32698
Info
Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
| Bugtraq ID: | 32698 |
| Class: | Design Error |
| CVE: |
CVE-2008-6512 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Apr 13 2015 09:12PM |
| Credit: | Yair Amit |
| Vulnerable: |
Google Gears 0.5 |
| Not Vulnerable: |
Google Gears 0.5.4 |
Discussion
Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
Google Gears is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy when handling WorkerPool objects.
An attacker may violate the same-origin policy and obtain sensitive information, including authentication credentials for web applications. Other attacks are also possible.
Versions prior to Google Gears 0.5.4 are vulnerable.
Google Gears is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy when handling WorkerPool objects.
An attacker may violate the same-origin policy and obtain sensitive information, including authentication credentials for web applications. Other attacks are also possible.
Versions prior to Google Gears 0.5.4 are vulnerable.
Exploit / POC
Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
Attackers can use common tools to exploit this issue.
Attackers can use common tools to exploit this issue.
Solution / Fix
Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
Solution:
The vendor has released updates; please see the references for more information.
Solution:
The vendor has released updates; please see the references for more information.
References
Google Gears WorkerPool API 'allowCrossOrigin()' Same Origin Policy Violation Vulnerability
References:
References:
- Breaking Google Gears' Cross-Origin Communication Model (Yair Amit)
- Gears API History (Google)
- Gears Homepage (Google)