The SPDY protocol 3 and earlier, as used in Mozilla...
Vulnerability Description
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-4930
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091
- http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312
- http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.html
- https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltls
- http://www.theregister.co.uk/2012/09/14/crime_tls_attack/
- https://bugzilla.redhat.com/show_bug.cgi?id=857737
- http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
- http://www.ekoparty.org/2012/thai-duong.php
More from google
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.