Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-1617
Description:The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.
Test IDs: 1.3.6.1.4.1.25623.1.0.703456  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-1617
BugTraq ID: 81430
http://www.securityfocus.com/bid/81430
Debian Security Information: DSA-3456 (Google Search)
http://www.debian.org/security/2016/dsa-3456
https://security.gentoo.org/glsa/201603-09
RedHat Security Advisories: RHSA-2016:0072
http://rhn.redhat.com/errata/RHSA-2016-0072.html
http://www.securitytracker.com/id/1034801
SuSE Security Announcement: openSUSE-SU-2016:0249 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html
SuSE Security Announcement: openSUSE-SU-2016:0250 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html
SuSE Security Announcement: openSUSE-SU-2016:0271 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html
http://www.ubuntu.com/usn/USN-2877-1




© 1998-2025 E-Soft Inc. All rights reserved.