Security Advisory

CVE-2013-2853

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-07-10 10:00:00
Last updated 2024-08-06 15:52:20
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.