CVE-2016-1693: Medium severity debian linux vulnerability
browser/safebrowsing/srtfieldtrialwin.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chromecleanuptool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
Other sources
The following flaw was identified in the Chromium browser: http download of software removal tool.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=598752
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1693?
CVE-2016-1693 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2016-1693?
To fix CVE-2016-1693, upgrade your Google Chrome browser to version 51.0.2704.63 or later.
What types of attacks does CVE-2016-1693 allow?
CVE-2016-1693 allows attackers to perform man-in-the-middle attacks that can lead to spoofing of the Software Removal Tool.
Which versions of Google Chrome are affected by CVE-2016-1693?
All versions of Google Chrome prior to 51.0.2704.63 are affected by CVE-2016-1693.
Are any operating systems affected by CVE-2016-1693?
Yes, CVE-2016-1693 affects various operating systems including Red Hat, Debian, and SUSE Linux distributions.