SB2014081301 - Information disclosure in Debian Linux



SB2014081301 - Information disclosure in Debian Linux

Published: August 13, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014081301
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2014-3166)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.


Remediation

Install update from vendor's website.