CVE-2014-7948

EUVD-2014-7798
The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 40.0.2214.85
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
ignored
trusty
Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068
released
utopic
Fixed 40.0.2214.94-0ubuntu0.14.10.1.1110
released
vivid
Fixed 40.0.2214.94-0ubuntu1.1120
released
wily
Fixed 40.0.2214.94-0ubuntu1.1120
released
oxide-qt
lucid
dne
precise
dne
trusty
Fixed 1.4.2-0ubuntu0.14.04.1
released
utopic
Fixed 1.4.2-0ubuntu0.14.10.1
released
vivid
Fixed 1.4.2-0ubuntu1
released
wily
Fixed 1.4.2-0ubuntu1
released
Common Weakness Enumeration