CVE-2015-1296
chromium-browser: Character spoofing in omnibox
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.
Vulnerabilidad en la implementación UnescapeURLWithAdjustmentsImpl en net/base/escape.cc en Google Chrome en versiones anteriores a 45.0.2454.85, no impide que se visualicen caracteres Unicode LOCK en el omnibox, lo que facilita a atacantes remotos suplantar el icono de bloqueo SSL poniendo uno de estos caracteres al final de una URL, según lo demostrado por el omnibox en localizaciones para los lenguajes de derecha a izquierda.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-21 CVE Reserved
- 2015-09-03 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-254: 7PK - Security Features
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html | X_refsource_confirm | |
http://www.securitytracker.com/id/1033472 | Vdb Entry | |
https://code.google.com/p/chromium/issues/detail?id=421332 | X_refsource_confirm | |
https://codereview.chromium.org/1180393003 | X_refsource_confirm | |
https://codereview.chromium.org/1189553002 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-1712.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3351 | 2023-11-07 | |
https://security.gentoo.org/glsa/201603-09 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2015-1296 | 2015-09-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1259164 | 2015-09-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 44.0.2403 Search vendor "Google" for product "Chrome" and version " <= 44.0.2403" | - |
Affected
|