SB2011080902 - Permissions, Privileges, and Access Controls in Techland Chrome 



SB2011080902 - Permissions, Privileges, and Access Controls in Techland Chrome

Published: August 9, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011080902
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2008-7294)

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.


Remediation

Install update from vendor's website.