Vulnerability Name: | CVE-2015-1296 (CCN-106004) | ||||||||||||||||||||||||||||||||
Assigned: | 2015-09-01 | ||||||||||||||||||||||||||||||||
Published: | 2015-09-01 | ||||||||||||||||||||||||||||||||
Updated: | 2016-12-22 | ||||||||||||||||||||||||||||||||
Summary: | The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-254 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1296 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Patch, Vendor Advisory http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1586 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1873 Source: REDHAT Type: UNKNOWN RHSA-2015:1712 Source: DEBIAN Type: UNKNOWN DSA-3351 Source: SECTRACK Type: UNKNOWN 1033472 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=421332 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/1180393003/ Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/1189553002/ Source: XF Type: UNKNOWN google-chrome-cve20151296-spoofing(106004) Source: GENTOO Type: UNKNOWN GLSA-201603-09 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1296 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |