Total vulnerabilities in the database
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 14.10 | 14.10.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
google / chrome | - | 40.0.2214.115.x |
redhat / enterprise_linux_desktop_supplementary | 6.0 | 6.0.x |
redhat / enterprise_linux_workstation_supplementary | 6.0 | 6.0.x |
redhat / enterprise_linux_server_supplementary_eus | 6.6.z | 6.6.z.x |
redhat / enterprise_linux_server | 6.0 | 6.0.x |