CVE-2016-8508: Medium severity Yandex Yandex Browser vulnerability
Published Mar 1, 2017
·Updated
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
Affected Software
1 affected component
Yandex Yandex Browser<17.1.1.227
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8508?
CVE-2016-8508 is classified as a medium severity vulnerability that could lead to phishing attacks.
2
How do I fix CVE-2016-8508?
To fix CVE-2016-8508, update Yandex Browser to version 17.1.1.227 or later.
3
What kind of attack does CVE-2016-8508 facilitate?
CVE-2016-8508 allows attackers to prevent Protect warnings on malicious websites, making it easier to conduct phishing attacks.
4
Which versions of Yandex Browser are affected by CVE-2016-8508?
Yandex Browser versions prior to 17.1.1.227 are affected by CVE-2016-8508.
5
Is CVE-2016-8508 a client-side or server-side vulnerability?
CVE-2016-8508 is a client-side vulnerability that impacts how the Yandex Browser handles certain content types.