CVE-2015-1229: Medium severity ubuntu vulnerability
net/http/proxyclientsocket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1229?
CVE-2015-1229 has been categorized as a high-severity vulnerability due to its potential to allow cookie-injection attacks.
How do I fix CVE-2015-1229?
To mitigate CVE-2015-1229, update Google Chrome to version 41.0.2272.76 or newer.
What systems are affected by CVE-2015-1229?
CVE-2015-1229 affects Google Chrome versions up to 40.0.2214.115 and specific versions of Ubuntu and Red Hat Enterprise Linux.
What type of vulnerability is CVE-2015-1229?
CVE-2015-1229 is a proxy authentication vulnerability that can lead to cookie-injection attacks.
Can CVE-2015-1229 be exploited remotely?
Yes, CVE-2015-1229 can be exploited remotely by malicious proxy servers to conduct attacks.