CVE Database
/

CVE-2012-4929

Back to search

CVE-2012-4929

Published: Sep 15, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

SSRT101139
vendor-advisory
x_refsource_HP
RHSA-2013:0587
vendor-advisory
x_refsource_REDHAT
DSA-2579
vendor-advisory
x_refsource_DEBIAN
FEDORA-2013-4403
vendor-advisory
x_refsource_FEDORA
USN-1898-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2012:1420
vendor-advisory
x_refsource_SUSE
DSA-3253
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2013:0157
vendor-advisory
x_refsource_SUSE
APPLE-SA-2013-06-04-1
vendor-advisory
x_refsource_APPLE
JVNDB-2016-000129
third-party-advisory
x_refsource_JVNDB
USN-1627-1
vendor-advisory
x_refsource_UBUNTU
DSA-2627
vendor-advisory
x_refsource_DEBIAN
oval:org.mitre.oval:def:18920
vdb-entry
signature
x_refsource_OVAL
55704
vdb-entry
x_refsource_BID
USN-1628-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2013:0143
vendor-advisory
x_refsource_SUSE
HPSBUX02866
vendor-advisory
x_refsource_HP
JVN#65273415
third-party-advisory
x_refsource_JVN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now