CVE-2012-4929

EUVD-2012-4854
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
7.0
debiandebian_linux
8.0
googlechrome
*
mozillafirefox
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bookworm
2.4.62-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
bullseye
2.4.62-1~deb11u1
fixed
bullseye (security)
2.4.62-1~deb11u2
fixed
sid
2.4.62-3
fixed
squeeze
no-dsa
trixie
2.4.62-3
fixed
lighttpd
bookworm
1.4.69-1
fixed
bullseye
1.4.59-1+deb11u2
fixed
bullseye (security)
1.4.59-1+deb11u2
fixed
sid
1.4.76-1
fixed
squeeze
no-dsa
trixie
1.4.76-1
fixed
nginx
bookworm
1.22.1-9
fixed
bullseye
1.18.0-6.1+deb11u3
fixed
bullseye (security)
1.18.0-6.1+deb11u3
fixed
sid
1.26.0-3
fixed
squeeze
no-dsa
trixie
1.26.0-3
fixed
openssl
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
bullseye
1.1.1w-0+deb11u1
fixed
bullseye (security)
1.1.1w-0+deb11u2
fixed
sid
3.3.2-2
fixed
squeeze
no-dsa
trixie
3.3.2-2
fixed
pound
bullseye
3.0-2
fixed
sid
4.14-2
fixed
squeeze
no-dsa
trixie
4.14-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
hardy
Fixed 2.2.8-1ubuntu0.24
released
lucid
Fixed 2.2.14-5ubuntu8.10
released
natty
ignored
oneiric
Fixed 2.2.20-1ubuntu1.3
released
precise
Fixed 2.2.22-1ubuntu1.2
released
quantal
Fixed 2.2.22-6ubuntu2.1
released
raring
Fixed 2.2.22-6ubuntu3
released
saucy
Fixed 2.2.22-6ubuntu3
released
chromium-browser
hardy
dne
lucid
Fixed 23.0.1271.97-0ubuntu0.10.04.1
released
natty
ignored
oneiric
Fixed 23.0.1271.97-0ubuntu0.11.10.1
released
precise
Fixed 23.0.1271.97-0ubuntu0.12.04.1
released
quantal
not-affected
raring
not-affected
saucy
not-affected
nss
hardy
ignored
lucid
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
openssl
hardy
ignored
lucid
Fixed 0.9.8k-7ubuntu8.15
released
natty
ignored
oneiric
ignored
precise
Fixed 1.0.1-4ubuntu5.10
released
quantal
Fixed 1.0.1c-3ubuntu2.5
released
raring
Fixed 1.0.1c-4ubuntu8.1
released
saucy
Fixed 1.0.1e-2ubuntu1.1
released
openssl098
hardy
dne
lucid
dne
natty
dne
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
qt4-x11
hardy
ignored
lucid
Fixed 4:4.6.2-0ubuntu5.5
released
natty
ignored
oneiric
Fixed 4:4.7.4-0ubuntu8.2
released
precise
Fixed 4:4.8.1-0ubuntu4.3
released
quantal
Fixed 4:4.8.3+dfsg-0ubuntu3
released
raring
Fixed 4:4.8.3+dfsg-0ubuntu3
released
saucy
Fixed 4:4.8.3+dfsg-0ubuntu3
released
Common Weakness Enumeration
References