browser/safebrowsing/srtfieldtrialwin.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chromecleanuptool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "51.0.2704.79-0ubuntu0.14.04.1.1121"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "51.0.2704.79-0ubuntu0.14.04.1.1121"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "51.0.2704.79-0ubuntu0.14.04.1.1121"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "51.0.2704.79-0ubuntu0.14.04.1.1121"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "51.0.2704.79-0ubuntu0.14.04.1.1121"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "51.0.2704.79-0ubuntu0.16.04.1.1242"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "51.0.2704.79-0ubuntu0.16.04.1.1242"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "51.0.2704.79-0ubuntu0.16.04.1.1242"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "51.0.2704.79-0ubuntu0.16.04.1.1242"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "51.0.2704.79-0ubuntu0.16.04.1.1242"
}
]
}