Vulnerability Description
The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 36.0.1985.143 | |
| Apple | Mac Os X | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
| Android | - | |
| Debian | Debian Linux | 7.0 |
| Apple | Iphone Os | - |
References
- http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html
- http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html
- http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html
- http://secunia.com/advisories/59693
- http://secunia.com/advisories/59904
- http://secunia.com/advisories/60685
- http://secunia.com/advisories/60798
- http://security.gentoo.org/glsa/glsa-201408-16.xml
- http://www.debian.org/security/2014/dsa-3039
- http://www.ietf.org/mail-archive/web/tls/current/msg13345.html
- http://www.securityfocus.com/bid/69202
- http://www.securitytracker.com/id/1030732
- https://code.google.com/p/chromium/issues/detail?id=398925
- https://src.chromium.org/viewvc/chrome?revision=286598&view=revision
- https://src.chromium.org/viewvc/chrome?revision=288435&view=revision
FAQ
What is CVE-2014-3166?
CVE-2014-3166 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY c...
How severe is CVE-2014-3166?
CVE-2014-3166 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3166?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Apple Mac Os X, Linux Linux Kernel, Microsoft Windows, Google Android.