UBUNTU-CVE-2014-3166

    Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3166

    UBUNTU-CVE-2014-3166

    Published: 13 Aug 2014Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary:

    Details: The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.

    Affected packages

    Package

    Name: chromium-browser

    Purl: pkg:deb/ubuntu/[email protected]~pkg1042?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -37.0.2062.94-0ubuntu0.14.04.1~pkg1042

    Affected versions

    29.0.1547.65-0ubuntu2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High