CVE-2015-1296

EUVD-2015-1437
The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 44.0.2403
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
precise
ignored
trusty
Fixed 45.0.2454.85-0ubuntu0.14.04.1.1097
released
vivid
Fixed 45.0.2454.85-0ubuntu0.15.04.1.1181
released
wily
Fixed 45.0.2454.85-0ubuntu1.1198
released
oxide-qt
precise
dne
trusty
dne
vivid
not-affected
wily
not-affected
Common Weakness Enumeration