Vulnerability Description
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proxygen Project | Proxygen | <= 0.32.0 |
Related Weaknesses (CWE)
References
- https://groups.google.com/forum/#%21topic/facebook-proxygen/K8wCXbW4ihs
- https://groups.google.com/forum/#%21topic/facebook-proxygen/K8wCXbW4ihs
FAQ
What is CVE-2015-7264?
CVE-2015-7264 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
How severe is CVE-2015-7264?
CVE-2015-7264 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-7264?
Check the references section above for vendor advisories and patch information. Affected products include: Proxygen Project Proxygen.