Vulnerability CVE-2010-0556


Published: 2010-02-18   Modified: 2012-02-13

Description:
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Chrome Password Manager Cross Origin Weakness
Timothy D. Morga...
20.02.2010

Type:

CWE-255

(Credentials Management)

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Google -> Chrome 

 References:
http://code.google.com/p/chromium/issues/detail?id=32718
http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html
http://securitytracker.com/id?1023583
http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
http://www.securityfocus.com/archive/1/509543/100/0/threaded
http://www.securityfocus.com/bid/38177
http://www.vsecurity.com/advisory/20100215-1.txt
http://www.vupen.com/english/advisories/2010/0361
https://exchange.xforce.ibmcloud.com/vulnerabilities/56216
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14407

Copyright 2024, cxsecurity.com

 

Back to Top