---
title: "CVE-2016-7152\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-7152?format=md
keywords: index, follow
---

# CVE-2016-7152

Publication date 6 September 2016

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2016-7152?format=md#impact-score)

Toggle side navigation

## Description

The HTTPS protocol does not consider the role of the TCP congestion window
in providing information about content length, which makes it easier for
remote attackers to obtain cleartext data by leveraging a web-browser
configuration in which third-party cookies are sent, aka a "HEIST" attack.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2016-7152?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 17.04 zesty | Ignored |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored |
| firefox | 17.04 zesty | Ignored |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| oxide-qt | 17.04 zesty | Ignored |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| thunderbird | 17.04 zesty | Ignored |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [seth-arnold](https://launchpad.net/~seth-arnold)

NVD had this CVE assigned to multiple browers as of 2016-09-12.
This CVE appears to cover a wide variety of browser side channels
demonstrating the time difference between first byte and last byte in
a response. This can be used both for compression-based determinations
of exact strings from requests that are reflected in responses as well
as uncompressed responses from sites that have disabled compression
to mitigate BEAST or CRIME.
The paper authors recommend users disable third-party cookies
in their browsers, with the caveat that many services will break.

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

We have no actionable item to fix this CVE.
Since we release new firefox, thunderbird and chromium upstream
releases, I'm marking this as ignored.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7152)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-7152)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-7152)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-7152)

### Other references

* <http://arstechnica.com/security/2016/08/new-attack-steals-ssns-e-mail-addresses-and-more-from-https-pages/>
* <https://tom.vg/papers/heist_blackhat2016.pdf>
* <https://www.blackhat.com/docs/us-16/materials/us-16-VanGoethem-HEIST-HTTP-Encrypted-Information-Can-Be-Stolen-Through-TCP-Windows-wp.pdf>
* <https://www.cve.org/CVERecord?id=CVE-2016-7152>
