Back to search
CVE-2016-7152
Published: Sep 6, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1036741
vdb-entry
x_refsource_SECTRACK
1036742
vdb-entry
x_refsource_SECTRACK
92769
vdb-entry
x_refsource_BID
https://tom.vg/papers/heist_blackhat2016.pdf
x_refsource_MISC
1036745
vdb-entry
x_refsource_SECTRACK
1036744
vdb-entry
x_refsource_SECTRACK
1036743
vdb-entry
x_refsource_SECTRACK
1036746
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now