Vulnerability Name: | CVE-2014-3166 (CCN-95248) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2014-08-12 | ||||||||||||||||||||||||||||||||||||
Published: | 2014-08-12 | ||||||||||||||||||||||||||||||||||||
Updated: | 2022-11-10 | ||||||||||||||||||||||||||||||||||||
Summary: | The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-3166 Source: CONFIRM Type: Release Notes, Vendor Advisory http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html Source: CONFIRM Type: Release Notes, Vendor Advisory http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Release Notes, Vendor Advisory http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html Source: SECUNIA Type: Broken Link, Third Party Advisory 59693 Source: SECUNIA Type: Broken Link, Third Party Advisory 59904 Source: SECUNIA Type: Broken Link, Third Party Advisory 60685 Source: SECUNIA Type: Broken Link, Third Party Advisory 60798 Source: GENTOO Type: Third Party Advisory GLSA-201408-16 Source: DEBIAN Type: Third Party Advisory DSA-3039 Source: MLIST Type: Third Party Advisory [tls] 20140810 Re: Inter-protocol attacks Source: BID Type: Broken Link, Third Party Advisory, VDB Entry 69202 Source: CCN Type: BID-69202 Google Chrome CVE-2014-3166 Information Disclosure Vulnerability Source: SECTRACK Type: Broken Link, Third Party Advisory, VDB Entry 1030732 Source: CONFIRM Type: Exploit, Issue Tracking, Mailing List, Vendor Advisory https://code.google.com/p/chromium/issues/detail?id=398925 Source: XF Type: UNKNOWN google-chrome-cve20143166-info-disc(95248) Source: CONFIRM Type: Third Party Advisory https://src.chromium.org/viewvc/chrome?revision=286598&view=revision Source: CONFIRM Type: Third Party Advisory https://src.chromium.org/viewvc/chrome?revision=288435&view=revision Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-3166 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |