Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
BID:36479
Info
Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 36479 |
| Class: | Design Error |
| CVE: |
CVE-2009-3456 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Dan Kaminsky and Moxie Marlinspike |
| Vulnerable: |
Google Chrome 3.0.195 .21 Google Chrome 2.0.172 .43 Google Chrome 2.0.172 .37 Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 1.0.154 .61 Google Chrome 3.0 Beta Google Chrome 1.0.154.65 Google Chrome 1.0.154.64 Google Chrome 1.0.154.59 Google Chrome 1.0.154.55 Google Chrome 1.0.154.53 Google Chrome 1.0.154.48 Google Chrome 1.0.154.46 Google Chrome 1.0.154.36 |
| Not Vulnerable: | |
Discussion
Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Google Chrome is prone to a security-bypass vulnerability because it fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Google Chrome is prone to a security-bypass vulnerability because it fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Attackers use man-in-the-middle attacks to exploit this issue.
Attackers use man-in-the-middle attacks to exploit this issue.
Solution / Fix
Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Google Chrome NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- Google Chrome Homepage (Google)
- More Tricks For Defeating SSL (Moxie Marlinspike)
- Null Prefix Attacks Against SSL/TLS Certificates (Moxie Marlinspike)
- SSL flaw revealed at Black Hat (Wendy Grossman)
- Vulnerabilities Allow Attacker to Impersonate Any Website (Kim Zetter)