Lucene search

K
cve[email protected]CVE-2015-1269
HistoryJun 26, 2015 - 2:59 p.m.

CVE-2015-1269

2015-06-2614:59:03
CWE-254
web.nvd.nist.gov
55
cve-2015-1269
google chrome
dns hostnames
hsts
hpkp
access restrictions
remote attackers

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8.8

Confidence

High

EPSS

0.006

Percentile

79.0%

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

Affected configurations

NVD
Node
googlechromeRange43.0.2357.81
VendorProductVersionCPE
googlechromecpe:/a:google:chrome::::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8.8

Confidence

High

EPSS

0.006

Percentile

79.0%