The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Aug 28, 2015 | Sep 15, 2012 |
| Apple Osx Openssl | — | Apply OS X security update 2013-002Upgrade macOS to the latest version | Jun 20, 2013 | Sep 15, 2012 |
| Centos_linux | — | Upgrade openssl-staticUpgrade opensslUpgrade openssl-develUpgrade openssl-perl | Dec 1, 2016 | Sep 15, 2012 |
| Debian | — | Upgrade nginxUpgrade lighttpdUpgrade opensslUpgrade poundUpgrade apache2 | Jul 30, 2024 | Sep 15, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 9, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 15, 2012 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Hpux | — | Update hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest versionUpdate hpuxws22APCH32.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxws22APCH32.APACHE to the latest version | Aug 11, 2017 | Sep 15, 2012 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade openssl-develUpgrade opensslUpgrade openssl-static | May 13, 2016 | Sep 15, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2012 |
| Suse | — | Upgrade libqt4-private-headers-develUpgrade libqt4Upgrade libQtWebKit4-32bitUpgrade libqt4-x11-debuginfoUpgrade libopenssl-devel-32bitUpgrade libqt4-debugsourceUpgrade libqt4-32bitUpgrade libqt4-x11Upgrade libqt4-x11-debuginfo-x86Upgrade libqt4-sql-mysql-x86Upgrade libqt4-sql-debuginfoUpgrade libqt4-sql-sqlite-debuginfo-32bitUpgrade qt4-x11-toolsUpgrade libqt4-develUpgrade libqt4-sql-postgresql-32bitUpgrade libqt4-sql-mysql-32bitUpgrade libqt4-sqlUpgrade openssl-develUpgrade openssl-devel-32bitUpgrade libQtWebKit-develUpgrade libqt4-x86Upgrade libqt4-qt3support-debuginfo-x86Upgrade libqt4-devel-debuginfoUpgrade sle-sdk-releaseUpgrade libqt4-debuginfo-32bitUpgrade libqt4-sql-unixodbcUpgrade libqt4-sql-postgresql-x86Upgrade libQtWebKit4Upgrade libqt4-sql-x86Upgrade libqt4-sql-mysqlUpgrade libqt4-sql-unixODBC-x86Upgrade libqt4-sql-sqliteUpgrade openssl-x86Upgrade libqt4-sql-sqlite-32bitUpgrade opensslUpgrade libqt4-devel-docUpgrade libqt4-x11-debuginfo-32bitUpgrade openssl-64bitUpgrade openssl-devel-64bitUpgrade libqt4-sql-sqlite-x86Upgrade libqt4-x11-x86Upgrade libqt4-sql-postgresqlUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0Upgrade libqt4-sql-sqlite-debuginfo-x86Upgrade libqt4-debuginfoUpgrade libqt4-devel-doc-dataUpgrade libqt4-x11-32bitUpgrade libqt4-qt3support-x86Upgrade openssl-32bitUpgrade libqt4-qt3support-debuginfo-32bitUpgrade libqt4-sql-debuginfo-32bitUpgrade libqt4-qt3supportUpgrade libQtWebKit4-x86Upgrade libopenssl-develUpgrade libqt4-sql-pluginsUpgrade libqt4-sql-32bitUpgrade libqt4-qt3support-debuginfoUpgrade libqt4-sql-debuginfo-x86Upgrade libqt4-sql-sqlite-debuginfoUpgrade openssl-docUpgrade libqt4-sql-unixodbc-32bitUpgrade libqt4-qt3support-32bitUpgrade libqt4-debuginfo-x86 | Dec 12, 2013 | Sep 15, 2012 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8Upgrade apache2.2-commonUpgrade libqt4-network | Nov 8, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub