oss-sec mailing list archives

Re: CVE Request?: konqueror - https uses all ciphers, even weak ones


From: Jann Horn <jann () thejh net>
Date: Tue, 4 Mar 2014 13:33:22 +0100

On Tue, Mar 04, 2014 at 12:28:21PM +0000, John Haxby wrote:

On 4 Mar 2014, at 11:24, Daniel Kahn Gillmor <dkg () fifthhorseman net> wrote:

Google Chrome doesn’t permit the link though, it just crashes :)

On what platform?  Is this for any connection, or just for a primary
connection?  That is, can any web site can crash google chrome with <img
src="https://demo.cmrg.net/"; /> ?

(sorry, i don't have either chrome or safari handy to test it myself
right now)

Chrome crashes on both Linux and Mavericks.

Could this be https://code.google.com/p/chromium/issues/detail?id=91341 or so?

Attachment: signature.asc
Description: Digital signature


Current thread: