Google Chrome Secure Cookie Security Bypass Vulnerability
BID:49133
Info
Google Chrome Secure Cookie Security Bypass Vulnerability
| Bugtraq ID: | 49133 |
| Class: | Design Error |
| CVE: |
CVE-2008-7294 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2008 12:00AM |
| Updated: | Nov 24 2008 12:00AM |
| Credit: | Chris Evans |
| Vulnerable: |
Google Chrome 3.0.195 .38 Google Chrome 3.0.195 .33 Google Chrome 3.0.195 .32 Google Chrome 3.0.195 .24 Google Chrome 3.0.195 .21 Google Chrome 3.0.195.37 Google Chrome 3.0.195.36 Google Chrome 3.0.195.27 Google Chrome 3.0.195.25 Google Chrome 3.0.195.2 Google Chrome 3.0.190.2 Google Chrome 3.0.182.2 |
| Not Vulnerable: |
Google Chrome 4.0.211.0 |
Discussion
Google Chrome Secure Cookie Security Bypass Vulnerability
Google Chrome is prone to a security-bypass vulnerability that affects secure cookies (cookies which are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
Versions prior to Chrome 4.0.211.0 are vulnerable.
Google Chrome is prone to a security-bypass vulnerability that affects secure cookies (cookies which are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
Versions prior to Chrome 4.0.211.0 are vulnerable.
Exploit / POC
Google Chrome Secure Cookie Security Bypass Vulnerability
Attackers can exploit this issue through conducting man-in-the-middle attacks.
Attackers can exploit this issue through conducting man-in-the-middle attacks.
Solution / Fix
Google Chrome Secure Cookie Security Bypass Vulnerability
Solution:
Updates are available. Please contact the vendor for more information.
Solution:
Updates are available. Please contact the vendor for more information.
References
Google Chrome Secure Cookie Security Bypass Vulnerability
References:
References:
- Browser Security Handbook (browsersec)
- Cookie forcing (Chris Evans)
- Cookie Forcing - Trust your cookies no more (Michael Coates)
- fyi: Strict Transport Security specification (JeffH)
- Google Chrome Homepage (Google)
- Some less obvious benefits of HSTS (Chris Evans)