extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.html | |
http://secunia.com/advisories/61482 | third party advisory |
http://security.gentoo.org/glsa/glsa-201408-16.xml | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.html | vendor advisory |
http://secunia.com/advisories/60268 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95470 | vdb entry |
http://www.securitytracker.com/id/1030767 | vdb entry |
http://www.securityfocus.com/bid/69400 | vdb entry |
http://www.debian.org/security/2014/dsa-3039 | vendor advisory |
https://src.chromium.org/viewvc/chrome?revision=285492&view=revision | |
https://crbug.com/390624 |