Vulnerability Description
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 8.0 |
| Chrome | <= 42.0.2311.60 |
Related Weaknesses (CWE)
References
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
- http://rhn.redhat.com/errata/RHSA-2015-0816.html
- http://ubuntu.com/usn/usn-2570-1
- http://www.debian.org/security/2015/dsa-3238
- http://www.securitytracker.com/id/1032209
- https://chromium.googlesource.com/chromium/src/net/+/2359906c4fdfa9d44b045755d23
- https://code.google.com/p/chromium/issues/detail?id=455215
- https://security.gentoo.org/glsa/201506-04
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
- http://rhn.redhat.com/errata/RHSA-2015-0816.html
- http://ubuntu.com/usn/usn-2570-1
FAQ
What is CVE-2015-1244?
CVE-2015-1244 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which ...
How severe is CVE-2015-1244?
CVE-2015-1244 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1244?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Debian Debian Linux, Google Chrome.