CVE-2014-7948
Publication date 22 January 2015
Last updated 24 July 2024
Ubuntu priority
The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
14.04 LTS trusty |
Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068
|
|
oxide-qt | ||
14.04 LTS trusty |
Fixed 1.4.2-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2476-1
- Oxide vulnerabilities
- 26 January 2015