Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1269

Опубликовано: 26 июн. 2015
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

РелизСтатусПримечание
devel

released

43.0.2357.130-0ubuntu1.1188
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [43.0.2357.130-0ubuntu0.14.04.1.1092]]
precise

ignored

trusty

released

43.0.2357.130-0ubuntu0.14.04.1.1092
trusty/esm

DNE

trusty was released [43.0.2357.130-0ubuntu0.14.04.1.1092]
upstream

released

43.0.2357.130
utopic

released

43.0.2357.130-0ubuntu0.14.10.1.1134
vivid

released

43.0.2357.130-0ubuntu0.15.04.1.1174
wily

released

43.0.2357.130-0ubuntu1.1188

Показывать по

РелизСтатусПримечание
devel

released

1.7.9-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.7.9-0ubuntu0.14.04.1]]
precise

DNE

trusty

released

1.7.9-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1.7.9-0ubuntu0.14.04.1]
upstream

released

1.7.9
utopic

released

1.7.9-0ubuntu0.14.10.1
vivid

released

1.7.9-0ubuntu0.15.04.1
wily

released

1.7.9-0ubuntu1

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

nvd
больше 10 лет назад

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

debian
больше 10 лет назад

The DecodeHSTSPreloadRaw function in net/http/transport_security_state ...

github
больше 3 лет назад

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти ограничения доступа

4.3 Medium

CVSS2