ISOMAN

CVE

CVE-2015-1244

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

Severity
MEDIUM
CVSS
5
Published
Modified

Linked Releases

References

  1. http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
  2. http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
  3. http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
  4. http://rhn.redhat.com/errata/RHSA-2015-0816.html
  5. http://ubuntu.com/usn/usn-2570-1
  6. http://www.debian.org/security/2015/dsa-3238
  7. http://www.securitytracker.com/id/1032209
  8. https://chromium.googlesource.com/chromium/src/net/+/2359906c4fdfa9d44b045755d23fe5327c10e010
  9. https://code.google.com/p/chromium/issues/detail?id=455215
  10. https://security.gentoo.org/glsa/201506-04
  11. http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
  12. http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
  13. http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
  14. http://rhn.redhat.com/errata/RHSA-2015-0816.html
  15. http://ubuntu.com/usn/usn-2570-1
  16. http://www.debian.org/security/2015/dsa-3238
  17. http://www.securitytracker.com/id/1032209
  18. https://chromium.googlesource.com/chromium/src/net/+/2359906c4fdfa9d44b045755d23fe5327c10e010
  19. https://code.google.com/p/chromium/issues/detail?id=455215
  20. https://security.gentoo.org/glsa/201506-04