CVE-2016-5137
published 2016-07-23CVE-2016-5137: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in…
PriorityP419medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.28%
67.3th percentile
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 51.0.2704.106 | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jc87-h9fr-rr78: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2016-5137 [MEDIUM] CWE-200 GHSA-jc87-h9fr-rr78: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution.
OSV
oxide-qt vulnerabilities
osv·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovered that Blink does not disable frame navigation during a
det
OSV
CVE-2016-5137: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource
osv·2016-07-23·CVSS 4.3
CVE-2016-5137 [MEDIUM] CVE-2016-5137: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovere
Red Hat
chromium-browser: history sniffing with hsts and csp
vendor_redhat·2016-07-20·CVSS 4.3
CVE-2016-5137 [MEDIUM] chromium-browser: history sniffing with hsts and csp
chromium-browser: history sniffing with hsts and csp
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5137 chromium-browser: history sniffing with hsts and csp
bugzilla·2016-07-21·CVSS 4.3
CVE-2016-5137 [MEDIUM] CVE-2016-5137 chromium-browser: history sniffing with hsts and csp
CVE-2016-5137 chromium-browser: history sniffing with hsts and csp
The following flaw was identified in the Chromium browser: history sniffing with hsts and csp.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=625945
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1485 https://rhn.redhat.com/errata/RHSA-2016-1485.html
Bugzilla
Probe browser history via HSTS/301 redirect + CSP
bugzilla·2016-07-06
[MEDIUM] Probe browser history via HSTS/301 redirect + CSP
Probe browser history via HSTS/301 redirect + CSP
Created attachment 8768537
csp probing.html
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
Expected results:
This is an updated version of the Sniffly attack (for the original attack, see https://bugs.chromium.org/p/chromium/issues/detail?id=544765). The original Sniffly vulnerability was fixed by making the CSP directive "img-src http:" === "img-src http: https:". But I find a way to bypass this fix, and make it possible again to probe which domains or URLs have been visited by users: the new trick is to use "Content-Security-Policy: img-src http://example.com:80". It allows http://example.com, but blocks https://example.com. This means by set
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2125873003https://crbug.com/625945https://security.gentoo.org/glsa/201610-09http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2125873003https://crbug.com/625945https://security.gentoo.org/glsa/201610-09
2016-07-23
Published