CVE-2015-7264: Critical severity proxygen vulnerability
Published Apr 10, 2017
·Updated
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
Affected Software
1 affected component
Proxygen Project Proxygen<=0.32.0
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-7264?
CVE-2015-7264 has been classified as a high severity vulnerability due to its potential for hijacking and injection attacks.
2
How do I fix CVE-2015-7264?
To mitigate CVE-2015-7264, upgrade to Proxygen version 0.32.1 or later where the vulnerability is addressed.
3
What software is affected by CVE-2015-7264?
CVE-2015-7264 affects Facebook Proxygen versions up to 0.32.0.
4
What type of attacks can CVE-2015-7264 enable?
CVE-2015-7264 may allow attackers to perform hijacking and injection attacks due to the truncated field in the SPDY/2 codec.
5
When was CVE-2015-7264 disclosed?
CVE-2015-7264 was disclosed prior to November 9, 2015.