5
CVSSv2

CVE-2015-1229

Published: 09/03/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

net/http/proxy_client_socket.cc in Google Chrome prior to 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

google chrome

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

redhat enterprise linux server 6.0

Vendor Advisories

Several security issues were fixed in Oxide ...
net/http/proxy_client_socketcc in Google Chrome before 410227276 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response ...