CVE-2010-0643: Infoleak
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0643?
CVE-2010-0643 has been rated as a medium severity vulnerability.
How do I fix CVE-2010-0643?
To fix CVE-2010-0643, upgrade to Google Chrome version 4.0.249.89 or later.
What type of information can be leaked due to CVE-2010-0643?
CVE-2010-0643 can potentially expose sensitive information about the identity of a client user.
Which versions of Google Chrome are affected by CVE-2010-0643?
All versions of Google Chrome before 4.0.249.89 are affected by CVE-2010-0643.
How does CVE-2010-0643 work?
CVE-2010-0643 allows remote HTTP servers to log connections made directly by Chrome when proxy servers are unavailable.