UBUNTU-CVE-2016-7153
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-7153
Summary:
Details: The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
References: https://ubuntu.com/security/CVE-2016-7153, http://arstechnica.com/security/2016/08/new-attack-steals-ssns-e-mail-addresses-and-more-from-https-pages/, https://tom.vg/papers/heist_blackhat2016.pdf, https://www.blackhat.com/docs/us-16/materials/us-16-VanGoethem-HEIST-HTTP-Encrypted-Information-Can-Be-Stolen-Through-TCP-Windows-wp.pdf, https://www.cve.org/CVERecord?id=CVE-2016-7153
Affected packages
Package
Name: oxide-qt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
