translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.
References
Link | Resource |
---|---|
http://googlechromereleases.blogspot.com/2012/02/chrome-stable-update.html | Release Notes Vendor Advisory |
http://code.google.com/p/chromium/issues/detail?id=112236 | Broken Link |
http://googlechromereleases.blogspot.com/2012/02/dev-channel-update_10.html | Release Notes Vendor Advisory |
http://src.chromium.org/viewvc/chrome?view=rev&revision=120113 | Issue Tracking Patch Vendor Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15025 | Third Party Advisory |
http://secunia.com/advisories/48016 | Not Applicable |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2012-02-16 12:55
Updated : 2020-04-16 09:49
NVD link : CVE-2011-3022
Mitre link : CVE-2011-3022
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
- chrome