Tracker / CVE-2017-5120
CVE-2017-5120
Media 6.5
Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML page. In other words, Chrome could transmit cleartext even though the user had entered an https URL, because of a misdesigned workaround for cases where the domain name in a URL almost matches the domain name in an X.509 server certificate (but differs in the initial "www." substring).
Prodotti e versioni affette
| debian | debian_linux |
|---|---|
| chrome · … → 61.0.3163.79 | |
| chrome · … → 61.0.3163.81 | |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_workstation |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.