CVE-2011-3061

Google Chrome < 18.0.1025.142 - Improper Certificate Validation in SPDY Proxy

Title source: llm
STIX 2.1

Description

Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026877
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74411
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48618
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48691
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/80739
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52762
Vendor Advisory x_refsource_confirm
http://code.google.com/p/chromium/issues/detail?id=116398
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48763

Scores

EPSS 0.0096
EPSS Percentile 57.0%

Details

CWE
CWE-295
Status published
Products (1)
google/chrome < 18.0.1025.142
Published Mar 30, 2012
Tracked Since Feb 18, 2026