LWN.net Logo

libqt4: CRIME attack

Package(s):libqt4 CVE #(s):CVE-2012-4929
Created:October 31, 2012 Updated:April 3, 2013
Description: From the CVE entry:

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

Alerts:
openSUSE openSUSE-SU-2012:1420-1 2012-10-31
Ubuntu USN-1627-1 2012-11-08
Ubuntu USN-1628-1 2012-11-08
Debian DSA-2579-1 2012-11-30
openSUSE openSUSE-SU-2013:0143-1 2013-01-23
openSUSE openSUSE-SU-2013:0157-1 2013-01-23
Debian DSA-2626-1 2013-02-17
Debian DSA-2627-1 2013-02-17
Mageia MGASA-2013-0053 2013-02-16
Red Hat RHSA-2013:0587-01 2013-03-04
Scientific Linux SL-open-20130304 2013-03-04
CentOS CESA-2013:0587 2013-03-05
Oracle ELSA-2013-0587 2013-03-04
Oracle ELSA-2013-0587 2013-03-05
CentOS CESA-2013:0587 2013-03-09
Fedora FEDORA-2013-4403 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds