SB2019100814 - Spoofing attack in Internet Explorer and Edge
Published: October 8, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2019-0608)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of HTTP response headers. A remote attacker that controls a web server can send specially crafted HTTP response headers and impersonate a user request by crafting HTTP queries.
2) Input validation error (CVE-ID: CVE-2019-1357)
The vulnerability allows a remote attacker to spoofing attack.
The vulnerability exists due to insufficient validation of browser cookies. A remote attacker can send a specially crafted HTTP response and overwrite a secure cookie with an insecure one. This can be used to construct an attack chain against applications that rely on cookie security.
Remediation
Install update from vendor's website.