Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome 安全漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 Google Chrome 40.0.2214.91之前版本的content/browser/appcache/appcache_update_job.cc文件中的‘AppCacheUpdateJob::URLFetcher::OnResponseStarted’函数存在安全漏洞,该漏洞源于程序没有正确验证X.509证书。攻击者可借助特制的证书利用该漏洞实施中间人攻击,伪造HTML5应用程序内容。
CVSS Information
N/A
Vulnerability Type
N/A