|
Google Chrome contains a NULL pointer dereference flaw in the 'HttpNetworkTransaction::HandleAuthChallenge' functin [net/http/http_network_transaction.cc] that may allow a denial of service. The issue is triggered when handling "HTTP Proxy Authentication Required" responses from a HTTPS server via a non-authenticating proxy. With a specially crafted response, a context-dependent attacker can cause the browser to crash.
|