First published: Fri Mar 10 2017(Updated: )
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebKitGTK+ | <=2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2330 has a medium severity rating due to its potential for exposing sensitive data in secure HTTP requests.
To fix CVE-2015-2330, upgrade WebKitGTK+ to version 2.6.6 or later.
CVE-2015-2330 can be exploited by remote attackers to view secure HTTP requests, including secure cookies.
WebKitGTK+ versions prior to 2.6.6, specifically up to and including 2.6.5, are affected by CVE-2015-2330.
CVE-2015-2330 allows attackers to view secure HTTP request data, including sensitive information like cookies.