CVE-2015-1263

Publication date 20 May 2015

Last updated 24 July 2024


Ubuntu priority

Description

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

Status

Package Ubuntu Release Status
chromium-browser 15.10 wily
Fixed 43.0.2357.81-0ubuntu1.1179
15.04 vivid
Fixed 43.0.2357.81-0ubuntu0.15.04.1.1170
14.10 utopic
Fixed 43.0.2357.81-0ubuntu0.14.10.1.1131
14.04 LTS trusty
Fixed 43.0.2357.81-0ubuntu0.14.04.1.1089
12.04 LTS precise Ignored
oxide-qt 15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release