SB2019100814 - Spoofing attack in Internet Explorer and Edge



SB2019100814 - Spoofing attack in Internet Explorer and Edge

Published: October 8, 2019

Security Bulletin ID SB2019100814
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2019-0608)

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of HTTP response headers. A remote attacker that controls a web server can send specially crafted HTTP response headers and impersonate a user request by crafting HTTP queries.


2) Input validation error (CVE-ID: CVE-2019-1357)

The vulnerability allows a remote attacker to spoofing attack.

The vulnerability exists due to insufficient validation of browser cookies. A remote attacker can send a specially crafted HTTP response and overwrite a secure cookie with an insecure one. This can be used to construct an attack chain against applications that rely on cookie security.


Remediation

Install update from vendor's website.