Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://code.google.com/p/chromium/issues/detail?id=30801 | vendor advisory |
http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14292 | vdb entry third party advisory signature |
http://code.google.com/p/chromium/issues/detail?id=33445 | vendor advisory |