CVE-2015-1296

Publication date 3 September 2015

Last updated 24 July 2024


Ubuntu priority

The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 15.10 wily
Fixed 45.0.2454.85-0ubuntu1.1198
15.04 vivid
Fixed 45.0.2454.85-0ubuntu0.15.04.1.1181
14.04 LTS trusty
Fixed 45.0.2454.85-0ubuntu0.14.04.1.1097
12.04 LTS precise Ignored
oxide-qt 15.10 wily
Not affected
15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Notes


chrisccoulson

URL displayed to the user in Oxide embedders is decoded by Qt