CVE-2015-1229
Published: 8 March 2015
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
Priority
Status
Package | Release | Status |
---|---|---|
chromium-browser Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Ignored
|
|
trusty |
Released
(41.0.2272.76-0ubuntu0.14.04.1.1076)
|
|
upstream |
Released
(41.0.2272.76)
|
|
utopic |
Released
(41.0.2272.76-0ubuntu0.14.10.1.1118)
|
|
vivid |
Released
(41.0.2272.76-0ubuntu1.1134)
|
|
wily |
Released
(41.0.2272.76-0ubuntu1.1134)
|
|
oxide-qt Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Does not exist
|
|
trusty |
Released
(1.5.5-0ubuntu0.14.04.3)
|
|
upstream |
Released
(1.5.5)
|
|
utopic |
Released
(1.5.5-0ubuntu0.14.10.2)
|
|
vivid |
Released
(1.5.5-0ubuntu1)
|
|
wily |
Released
(1.5.5-0ubuntu1)
|