CVE-2012-4929

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
debiandebian_linux
7.0
debiandebian_linux
8.0
googlechrome
*
mozillafirefox
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bullseye
2.4.62-1~deb11u1
fixed
squeeze
no-dsa
bullseye (security)
2.4.62-1~deb11u2
fixed
bookworm
2.4.62-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
sid
2.4.62-3
fixed
trixie
2.4.62-3
fixed
lighttpd
bullseye (security)
1.4.59-1+deb11u2
fixed
bullseye
1.4.59-1+deb11u2
fixed
squeeze
no-dsa
bookworm
1.4.69-1
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
nginx
bullseye (security)
1.18.0-6.1+deb11u3
fixed
bullseye
1.18.0-6.1+deb11u3
fixed
squeeze
no-dsa
bookworm
1.22.1-9
fixed
sid
1.26.0-3
fixed
trixie
1.26.0-3
fixed
openssl
bullseye
1.1.1w-0+deb11u1
fixed
squeeze
no-dsa
bullseye (security)
1.1.1w-0+deb11u2
fixed
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
sid
3.3.2-2
fixed
trixie
3.3.2-2
fixed
pound
bullseye
3.0-2
fixed
squeeze
no-dsa
sid
4.14-2
fixed
trixie
4.14-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
saucy
Fixed 2.2.22-6ubuntu3
released
raring
Fixed 2.2.22-6ubuntu3
released
quantal
Fixed 2.2.22-6ubuntu2.1
released
precise
Fixed 2.2.22-1ubuntu1.2
released
oneiric
Fixed 2.2.20-1ubuntu1.3
released
natty
ignored
lucid
Fixed 2.2.14-5ubuntu8.10
released
hardy
Fixed 2.2.8-1ubuntu0.24
released
chromium-browser
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
Fixed 23.0.1271.97-0ubuntu0.12.04.1
released
oneiric
Fixed 23.0.1271.97-0ubuntu0.11.10.1
released
natty
ignored
lucid
Fixed 23.0.1271.97-0ubuntu0.10.04.1
released
hardy
dne
nss
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
not-affected
hardy
ignored
openssl
saucy
Fixed 1.0.1e-2ubuntu1.1
released
raring
Fixed 1.0.1c-4ubuntu8.1
released
quantal
Fixed 1.0.1c-3ubuntu2.5
released
precise
Fixed 1.0.1-4ubuntu5.10
released
oneiric
ignored
natty
ignored
lucid
Fixed 0.9.8k-7ubuntu8.15
released
hardy
ignored
openssl098
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
natty
dne
lucid
dne
hardy
dne
qt4-x11
saucy
Fixed 4:4.8.3+dfsg-0ubuntu3
released
raring
Fixed 4:4.8.3+dfsg-0ubuntu3
released
quantal
Fixed 4:4.8.3+dfsg-0ubuntu3
released
precise
Fixed 4:4.8.1-0ubuntu4.3
released
oneiric
Fixed 4:4.7.4-0ubuntu8.2
released
natty
ignored
lucid
Fixed 4:4.6.2-0ubuntu5.5
released
hardy
ignored
Common Weakness Enumeration
References