CVE-2014-3166
Summary
| CVE | CVE-2014-3166 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-13 04:57:12 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Re: [TLS] Inter-protocol attacks | af854a3a-2127-422b-91ae-364da2661108 | www.ietf.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [chrome] Revision 286598 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Chromium: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-3039-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Google Chrome CVE-2014-3166 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Chrome Releases: Chrome for Android Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| Chrome Releases: Chrome for iOS Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| Security Advisory SA60685 - Google Chrome for iOS SPDY Information Disclosure Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Issue 398925 - chromium - Security: SPDY connection sharing logic errors allows for MITM - An open-source project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| [chrome] Revision 288435 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code and Obtain Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.