net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ubuntu_linux | Canonical | 14.04 (including) | 14.04 (including) |
| Ubuntu_linux | Canonical | 14.10 (including) | 14.10 (including) |
| Supplementary for Red Hat Enterprise Linux 6 | RedHat | chromium-browser-0:41.0.2272.76-1.el6_6 | * |
| Chromium-browser | Ubuntu | devel | * |
| Chromium-browser | Ubuntu | lucid | * |
| Chromium-browser | Ubuntu | precise | * |
| Chromium-browser | Ubuntu | trusty | * |
| Chromium-browser | Ubuntu | upstream | * |
| Chromium-browser | Ubuntu | utopic | * |
| Chromium-browser | Ubuntu | vivid | * |
| Chromium-browser | Ubuntu | wily | * |
| Oxide-qt | Ubuntu | devel | * |
| Oxide-qt | Ubuntu | trusty | * |
| Oxide-qt | Ubuntu | upstream | * |
| Oxide-qt | Ubuntu | utopic | * |
| Oxide-qt | Ubuntu | vivid | * |
| Oxide-qt | Ubuntu | wily | * |