VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1501
chrome: Cross-site request forgery (CSRF) vulnerability in ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1501

Original

Cross-site request forgery (CSRF) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-04-23
Source Information Category:
Advisory, Alert
Last Updated:
2010-04-26




Affected Product Tags
cpe:/a:google:chrome:1.0.154.53
cpe:/a:google:chrome:1.0.154.59
cpe:/a:google:chrome:1.0.154.64
cpe:/a:google:chrome:1.0.154.65
cpe:/a:google:chrome:2.0.169.0
cpe:/a:google:chrome:2.0.169.1
cpe:/a:google:chrome:2.0.170.0
cpe:/a:google:chrome:2.0.172.2
cpe:/a:google:chrome:2.0.172.27
cpe:/a:google:chrome:2.0.172.28
cpe:/a:google:chrome:2.0.172.30
cpe:/a:google:chrome:2.0.172.33
cpe:/a:google:chrome:2.0.172.37
cpe:/a:google:chrome:2.0.172.38
cpe:/a:google:chrome:2.0.172.8
cpe:/a:google:chrome:3.0.182.2
cpe:/a:google:chrome:3.0.195.2
cpe:/a:google:chrome:3.0.195.21
cpe:/a:google:chrome:3.0.195.24
cpe:/a:google:chrome:3.0.195.25
cpe:/a:google:chrome:3.0.195.27
cpe:/a:google:chrome:3.0.195.33
cpe:/a:google:chrome:3.0.195.36
cpe:/a:google:chrome:3.0.195.37
cpe:/a:google:chrome:3.0.195.38
cpe:/a:google:chrome:4.0.212.0
cpe:/a:google:chrome:4.0.212.1
cpe:/a:google:chrome:4.0.221.8
cpe:/a:google:chrome:4.0.222.0
cpe:/a:google:chrome:4.0.222.1
cpe:/a:google:chrome:4.0.222.12
cpe:/a:google:chrome:4.0.222.5
cpe:/a:google:chrome:4.0.223.0
cpe:/a:google:chrome:4.0.223.1
cpe:/a:google:chrome:4.0.223.2
cpe:/a:google:chrome:4.0.223.4
cpe:/a:google:chrome:4.0.223.5
cpe:/a:google:chrome:4.0.223.7
cpe:/a:google:chrome:4.0.223.8
cpe:/a:google:chrome:4.0.223.9
cpe:/a:google:chrome:4.0.224.0
cpe:/a:google:chrome:4.0.229.1
cpe:/a:google:chrome:4.0.235.0
cpe:/a:google:chrome:4.0.236.0
cpe:/a:google:chrome:4.0.237.0
cpe:/a:google:chrome:4.0.237.1
cpe:/a:google:chrome:4.0.239.0
cpe:/a:google:chrome:4.0.240.0
cpe:/a:google:chrome:4.0.241.0
cpe:/a:google:chrome:4.0.242.0
cpe:/a:google:chrome:4.0.243.0
cpe:/a:google:chrome:4.0.244.0
cpe:/a:google:chrome:4.0.245.0
cpe:/a:google:chrome:4.0.245.1
cpe:/a:google:chrome:4.0.246.0
cpe:/a:google:chrome:4.0.247.0
cpe:/a:google:chrome:4.0.248.0
cpe:/a:google:chrome:4.0.249.0
cpe:/a:google:chrome:4.0.249.1
cpe:/a:google:chrome:4.0.249.10
cpe:/a:google:chrome:4.0.249.11
cpe:/a:google:chrome:4.0.249.12
cpe:/a:google:chrome:4.0.249.14
cpe:/a:google:chrome:4.0.249.16
cpe:/a:google:chrome:4.0.249.17
cpe:/a:google:chrome:4.0.249.18
cpe:/a:google:chrome:4.0.249.19
cpe:/a:google:chrome:4.0.249.2
cpe:/a:google:chrome:4.0.249.20
cpe:/a:google:chrome:4.0.249.21
cpe:/a:google:chrome:4.0.249.22
cpe:/a:google:chrome:4.0.249.23
cpe:/a:google:chrome:4.0.249.24
cpe:/a:google:chrome:4.0.249.25
cpe:/a:google:chrome:4.0.249.26
cpe:/a:google:chrome:4.0.249.27
cpe:/a:google:chrome:4.0.249.28
cpe:/a:google:chrome:4.0.249.29
cpe:/a:google:chrome:4.0.249.3
cpe:/a:google:chrome:4.0.249.30
cpe:/a:google:chrome:4.0.249.31
cpe:/a:google:chrome:4.0.249.32
cpe:/a:google:chrome:4.0.249.33
cpe:/a:google:chrome:4.0.249.34
cpe:/a:google:chrome:4.0.249.35
cpe:/a:google:chrome:4.0.249.36
cpe:/a:google:chrome:4.0.249.37
cpe:/a:google:chrome:4.0.249.38
cpe:/a:google:chrome:4.0.249.39
cpe:/a:google:chrome:4.0.249.4
cpe:/a:google:chrome:4.0.249.40
cpe:/a:google:chrome:4.0.249.41
cpe:/a:google:chrome:4.0.249.42
cpe:/a:google:chrome:4.0.249.43
cpe:/a:google:chrome:4.0.249.44
cpe:/a:google:chrome:4.0.249.45
cpe:/a:google:chrome:4.0.249.46
cpe:/a:google:chrome:4.0.249.47
cpe:/a:google:chrome:4.0.249.48
cpe:/a:google:chrome:4.0.249.49
cpe:/a:google:chrome:4.0.249.5
cpe:/a:google:chrome:4.0.249.50
cpe:/a:google:chrome:4.0.249.51
cpe:/a:google:chrome:4.0.249.52
cpe:/a:google:chrome:4.0.249.53
cpe:/a:google:chrome:4.0.249.54
cpe:/a:google:chrome:4.0.249.55
cpe:/a:google:chrome:4.0.249.56
cpe:/a:google:chrome:4.0.249.57
cpe:/a:google:chrome:4.0.249.58
cpe:/a:google:chrome:4.0.249.59
cpe:/a:google:chrome:4.0.249.6
cpe:/a:google:chrome:4.0.249.61
cpe:/a:google:chrome:4.0.249.62
cpe:/a:google:chrome:4.0.249.63
cpe:/a:google:chrome:4.0.249.64
cpe:/a:google:chrome:4.0.249.65
cpe:/a:google:chrome:4.0.249.66
cpe:/a:google:chrome:4.0.249.67
cpe:/a:google:chrome:4.0.249.68
cpe:/a:google:chrome:4.0.249.69
cpe:/a:google:chrome:4.0.249.7
cpe:/a:google:chrome:4.0.249.70
cpe:/a:google:chrome:4.0.249.71
cpe:/a:google:chrome:4.0.249.72
cpe:/a:google:chrome:4.0.249.73
cpe:/a:google:chrome:4.0.249.74
cpe:/a:google:chrome:4.0.249.75
cpe:/a:google:chrome:4.0.249.76
cpe:/a:google:chrome:4.0.249.77
cpe:/a:google:chrome:4.0.249.78
cpe:/a:google:chrome:4.0.249.78:beta
cpe:/a:google:chrome:4.0.249.79
cpe:/a:google:chrome:4.0.249.8
cpe:/a:google:chrome:4.0.249.80
cpe:/a:google:chrome:4.0.249.81
cpe:/a:google:chrome:4.0.249.82
cpe:/a:google:chrome:4.0.249.89
cpe:/a:google:chrome:4.0.249.9
cpe:/a:google:chrome:4.0.250.0
cpe:/a:google:chrome:4.0.250.2
cpe:/a:google:chrome:4.0.251.0
cpe:/a:google:chrome:4.0.252.0
cpe:/a:google:chrome:4.0.254.0
cpe:/a:google:chrome:4.0.255.0
cpe:/a:google:chrome:4.0.256.0
cpe:/a:google:chrome:4.0.257.0
cpe:/a:google:chrome:4.0.258.0
cpe:/a:google:chrome:4.0.259.0
cpe:/a:google:chrome:4.0.260.0
cpe:/a:google:chrome:4.0.261.0
cpe:/a:google:chrome:4.0.262.0
cpe:/a:google:chrome:4.0.263.0
cpe:/a:google:chrome:4.0.264.0
cpe:/a:google:chrome:4.0.265.0
cpe:/a:google:chrome:4.0.266.0
cpe:/a:google:chrome:4.0.267.0
cpe:/a:google:chrome:4.0.268.0
cpe:/a:google:chrome:4.0.269.0
cpe:/a:google:chrome:4.0.271.0
cpe:/a:google:chrome:4.0.272.0
cpe:/a:google:chrome:4.0.275.0
cpe:/a:google:chrome:4.0.275.1
cpe:/a:google:chrome:4.0.276.0
cpe:/a:google:chrome:4.0.277.0
cpe:/a:google:chrome:4.0.278.0
cpe:/a:google:chrome:4.0.286.0
cpe:/a:google:chrome:4.0.287.0
cpe:/a:google:chrome:4.0.288.0
cpe:/a:google:chrome:4.0.288.1
cpe:/a:google:chrome:4.0.289.0
cpe:/a:google:chrome:4.0.290.0
cpe:/a:google:chrome:4.0.292.0
cpe:/a:google:chrome:4.0.294.0
cpe:/a:google:chrome:4.0.295.0
cpe:/a:google:chrome:4.0.296.0
cpe:/a:google:chrome:4.0.299.0
cpe:/a:google:chrome:4.0.300.0
cpe:/a:google:chrome:4.0.301.0
cpe:/a:google:chrome:4.0.302.0
cpe:/a:google:chrome:4.0.302.1
cpe:/a:google:chrome:4.0.302.2
cpe:/a:google:chrome:4.0.302.3
cpe:/a:google:chrome:4.0.303.0
cpe:/a:google:chrome:4.0.304.0
cpe:/a:google:chrome:4.0.305.0
cpe:/a:google:chrome:4.1.249.0
cpe:/a:google:chrome:4.1.249.1001
cpe:/a:google:chrome:4.1.249.1004
cpe:/a:google:chrome:4.1.249.1006
cpe:/a:google:chrome:4.1.249.1007
cpe:/a:google:chrome:4.1.249.1008
cpe:/a:google:chrome:4.1.249.1009
cpe:/a:google:chrome:4.1.249.1010
cpe:/a:google:chrome:4.1.249.1011
cpe:/a:google:chrome:4.1.249.1012
cpe:/a:google:chrome:4.1.249.1013
cpe:/a:google:chrome:4.1.249.1014
cpe:/a:google:chrome:4.1.249.1015
cpe:/a:google:chrome:4.1.249.1016
cpe:/a:google:chrome:4.1.249.1017
cpe:/a:google:chrome:4.1.249.1018
cpe:/a:google:chrome:4.1.249.1019
cpe:/a:google:chrome:4.1.249.1020
cpe:/a:google:chrome:4.1.249.1021
cpe:/a:google:chrome:4.1.249.1022
cpe:/a:google:chrome:4.1.249.1023
cpe:/a:google:chrome:4.1.249.1024
cpe:/a:google:chrome:4.1.249.1025
cpe:/a:google:chrome:4.1.249.1026
cpe:/a:google:chrome:4.1.249.1027
cpe:/a:google:chrome:4.1.249.1028
cpe:/a:google:chrome:4.1.249.1029
cpe:/a:google:chrome:4.1.249.1030
cpe:/a:google:chrome:4.1.249.1031
cpe:/a:google:chrome:4.1.249.1032
cpe:/a:google:chrome:4.1.249.1033
cpe:/a:google:chrome:4.1.249.1034
cpe:/a:google:chrome:4.1.249.1035
cpe:/a:google:chrome:4.1.249.1036
cpe:/a:google:chrome:4.1.249.1042
cpe:/a:google:chrome:4.1.249.1045
cpe:/a:google:chrome:4.1.249.1046
cpe:/a:google:chrome:4.1.249.1047
cpe:/a:google:chrome:4.1.249.1048
cpe:/a:google:chrome:4.1.249.1049
cpe:/a:google:chrome:4.1.249.1050
cpe:/a:google:chrome:4.1.249.1051
cpe:/a:google:chrome:4.1.249.1052
cpe:/a:google:chrome:4.1.249.1053
cpe:/a:google:chrome:4.1.249.1054
cpe:/a:google:chrome:4.1.249.1055
cpe:/a:google:chrome:4.1.249.1056
cpe:/a:google:chrome:4.1.249.1057
cpe:/a:google:chrome:4.1.249.1058 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
BID 39603




CONFIRM http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html




CONFIRM http://code.google.com/p/chromium/issues/detail?id=39698




SECUNIA 39544




Vulnerability Type Cross-Site Request Forgery (CSRF) (CWE-352)





Copyright © 2010 JPCERT/CC All Rights Reserved.