Back to search
CVE-2016-5672
Published: Aug 1, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to spoof SSL servers and obtain sensitive information via a crafted certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
92199
vdb-entry
x_refsource_BID
https://crosswalk-project.org/jira/browse/XWALK-6986
x_refsource_MISC
[crosswalk-help] 20160728 Crosswalk Security Advisory
mailing-list
x_refsource_MLIST
20160729 CVE-2016-5672: Intel Crosswalk SSL Prompt Issue
mailing-list
x_refsource_BUGTRAQ
VU#217871
third-party-advisory
x_refsource_CERT-VN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now