Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c4v-vhcv-h8xg

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.

Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

nvd
больше 16 лет назад

Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.

debian
больше 16 лет назад

Google Chrome before 2.0.172.43 does not prevent SSL connections to a ...

EPSS

Процентиль: 31%
0.00116
Низкий