Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
BID:49137
Info
Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
| Bugtraq ID: | 49137 |
| Class: | Design Error |
| CVE: |
CVE-2008-7298 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2008 12:00AM |
| Updated: | Nov 24 2008 12:00AM |
| Credit: | Chris Evans |
| Vulnerable: |
Open Handset Alliance Android 2.3.5 Open Handset Alliance Android 2.3.2 Open Handset Alliance Android 2.3.1 Open Handset Alliance Android 2.0.1 Open Handset Alliance Android 2.3.4 Open Handset Alliance Android 2.3 Open Handset Alliance Android 2.2 Open Handset Alliance Android 2.1.1 Open Handset Alliance Android 2.1 Open Handset Alliance Android 2.0 Open Handset Alliance Android 1.5 Open Handset Alliance Android 1.0 Open Handset Alliance Android 0 |
| Not Vulnerable: | |
Discussion
Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
Open Handset Alliance Android's web browser is prone to a security-bypass vulnerability that affects secure cookies (cookies which are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
Open Handset Alliance Android's web browser is prone to a security-bypass vulnerability that affects secure cookies (cookies which are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
Exploit / POC
Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
Attackers can exploit this issue through conducting man-in-the-middle attacks.
Attackers can exploit this issue through conducting man-in-the-middle attacks.
Solution / Fix
Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Open Handset Alliance Android Web Browser Secure Cookie Security Bypass Vulnerability
References:
References:
- Android Homepage (Open Handset Alliance)
- Browser Security Handbook (browsersec)
- Cookie forcing (Chris Evans)
- Cookie Forcing - Trust your cookies no more (Michael Coates)
- Some less obvious benefits of HSTS (Chris Evans)