Oval Definition:oval:org.mitre.oval:def:26626
Revision Date:2014-10-27Version:27
Title:Allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter
Description:Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-6166
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Google Chrome
Definition Synopsis
  • Google Chrome is installed
  • AND Check if the version of Google Chrome is less than 29.0.1547.57
  • BACK