Vulnerability CVE-2016-7152


Published: 2016-09-06

Description:
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Opera -> Opera 
Mozilla -> Firefox 
Microsoft -> EDGE 
Microsoft -> Internet explorer 
Google -> Chrome 
Apple -> Safari 

 References:
http://arstechnica.com/security/2016/08/new-attack-steals-ssns-e-mail-addresses-and-more-from-https-pages/
http://www.securityfocus.com/bid/92769
http://www.securitytracker.com/id/1036741
http://www.securitytracker.com/id/1036742
http://www.securitytracker.com/id/1036743
http://www.securitytracker.com/id/1036744
http://www.securitytracker.com/id/1036745
http://www.securitytracker.com/id/1036746
https://tom.vg/papers/heist_blackhat2016.pdf

Copyright 2024, cxsecurity.com

 

Back to Top