Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-3166
HistoryAug 13, 2014 - 12:00 a.m.

CVE-2014-3166

2014-08-1300:00:00
ubuntu.com
ubuntu.com
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.009

Percentile

83.1%

The Public Key Pinning (PKP) implementation in Google Chrome before
36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on
Android, does not correctly consider the properties of SPDY connections,
which allows remote attackers to obtain sensitive information by leveraging
the use of multiple domain names.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchchromium-browser< 37.0.2062.94-0ubuntu0.12.04.1~pkg909UNKNOWN
ubuntu14.04noarchchromium-browser< 37.0.2062.94-0ubuntu0.14.04.1~pkg1042UNKNOWN
ubuntu14.04noarchoxide-qt< 1.0.5-0ubuntu0.14.04.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.009

Percentile

83.1%