The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/chromium.Upgrade dev-lang/v8. | Oct 30, 2017 | Jul 10, 2013 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Jul 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub