Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
BID:57790
Info
Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
| Bugtraq ID: | 57790 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2013 12:00AM |
| Updated: | Feb 07 2013 12:00AM |
| Credit: | T355 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
Google Chrome is prone to a security weakness that may allow attackers to bypass intended security restrictions.
An attacker can exploit this weakness to bypass the security restrictions and perform silent HTTP Basic Authentication through various HTML tags. This can lead to various attacks.
Chrome 24.0.1312.57 is vulnerable; other versions may also be affected.
Google Chrome is prone to a security weakness that may allow attackers to bypass intended security restrictions.
An attacker can exploit this weakness to bypass the security restrictions and perform silent HTTP Basic Authentication through various HTML tags. This can lead to various attacks.
Chrome 24.0.1312.57 is vulnerable; other versions may also be affected.
Exploit / POC
Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Google Chrome 24.0.1312.57 HTTP Authentication Security Bypass Weakness
References:
References:
- Google Chrome Homepage (Google)