The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Aug 28, 2015 | Sep 15, 2012 |
| Apple Osx Openssl | — | Apply OS X security update 2013-002Upgrade macOS to the latest version | Jun 20, 2013 | Sep 15, 2012 |
| Centos_linux | — | Upgrade openssl-perlUpgrade openssl-develUpgrade openssl-staticUpgrade openssl | Dec 1, 2016 | Sep 15, 2012 |
| Debian | — | Upgrade lighttpdUpgrade nginxUpgrade poundUpgrade opensslUpgrade apache2 | Jul 30, 2024 | Sep 15, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 9, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 15, 2012 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Hpux | — | Update hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APCH32.APACHE to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22APCH32.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest version | Aug 11, 2017 | Sep 15, 2012 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-staticUpgrade openssl | May 13, 2016 | Sep 15, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2012 |
| Suse | — | Upgrade libqt4-sql-unixODBCUpgrade libopenssl0_9_8Upgrade libqt4-sql-32bitUpgrade libqt4-sql-postgresqlUpgrade libqt4-qt3support-x86Upgrade libqt4-x11-x86Upgrade openssl-docUpgrade openssl-1_0_0Upgrade libqt4-sql-unixODBC-32bitUpgrade libqt4-sql-mysqlUpgrade libQtWebKit4-x86Upgrade libopenssl-develUpgrade libqt4-qt3support-32bitUpgrade libqt4-sql-x86Upgrade libqt4-sql-sqlite-x86Upgrade libqt4-devel-docUpgrade libopenssl1_0_0-hmacUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0Upgrade wgetUpgrade openssl1-docUpgrade opensslUpgrade libqt4-devel-doc-dataUpgrade libqt4-sql-postgresql-x86Upgrade libopenssl0_9_8-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1-32bitUpgrade libqt4-qt3supportUpgrade libqt4-x11-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-1_0_0-develUpgrade libopenssl-fips-providerUpgrade libQtWebKit4Upgrade libqt4-sql-unixODBC-x86Upgrade libqt4-sql-sqliteUpgrade libqt4-sql-sqlite-32bitUpgrade libqt4-linguistUpgrade openssl1Upgrade libopenssl1-develUpgrade openssl-1_1Upgrade openssl-1_0_0-docUpgrade libqt4-develUpgrade qt4-x11-toolsUpgrade w3mUpgrade libqt4-sql-mysql-x86Upgrade libqt4-sql-postgresql-32bitUpgrade libqt4-private-headers-develUpgrade libqt4-x86Upgrade libqt4-sql-mysql-32bitUpgrade libopenssl0_9_8-hmacUpgrade libopenssl0_9_8-x86Upgrade libQtWebKit4-32bitUpgrade libopenssl-1_1-develUpgrade libqt4-sqlUpgrade wget-langUpgrade libqt4Upgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1_1Upgrade w3m-inline-imageUpgrade libqt4-32bitUpgrade libQtWebKit-develUpgrade libqt4-x11Upgrade libopenssl1_1-hmac | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8Upgrade libqt4-networkUpgrade apache2.2-common | Nov 8, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub