translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
http://src.chromium.org/viewvc/chrome?view=rev&revision=120113 | issue tracking patch vendor advisory |
http://code.google.com/p/chromium/issues/detail?id=112236 | broken link |
http://googlechromereleases.blogspot.com/2012/02/chrome-stable-update.html | release notes vendor advisory |
http://secunia.com/advisories/48016 | third party advisory not applicable |
http://googlechromereleases.blogspot.com/2012/02/dev-channel-update_10.html | release notes vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15025 | vdb entry third party advisory signature |