Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/chromium.Upgrade dev-lang/v8. | Oct 30, 2017 | Mar 30, 2012 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Apr 27, 2012 | Mar 30, 2012 |
| Suse | — | Upgrade chromium | Aug 9, 2024 | Jul 9, 2013 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Mar 30, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub