Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox/Google Chrome SPDY协议加密问题漏洞
Vulnerability Description
SPDY是Google开发的基于传输控制协议(TCP)的应用层协议。 Mozilla Firefox,Google Chrome及其他多个产品使用的SPDY协议3和之前版本中存在漏洞,该漏洞源于执行压缩数据加密时没有正确模糊未加密数据的长度。中间人攻击者可通过提交一系列猜测请求,观察到压缩数据长度的变化(也称CRIME攻击)来获取明文HTTP头信息,造成敏感信息泄露(如cookie信息)。
CVSS Information
N/A
Vulnerability Type
N/A