The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Aug 28, 2015 | Sep 15, 2012 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Jun 20, 2013 | Sep 15, 2012 |
| Centos_linux | — | Upgrade openssl-staticUpgrade opensslUpgrade openssl-develUpgrade openssl-perl | Dec 1, 2016 | Sep 15, 2012 |
| Debian | — | Upgrade lighttpdUpgrade nginxUpgrade apache2Upgrade opensslUpgrade pound | Jul 30, 2024 | Sep 15, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 9, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 15, 2012 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Hpux | — | Update hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest versionUpdate hpuxws22APCH32.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22APCH32.APACHE to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest version | Aug 11, 2017 | Sep 15, 2012 |
| Oracle_linux | — | Upgrade openssl-staticUpgrade opensslUpgrade openssl-perlUpgrade openssl-devel | May 13, 2016 | Sep 15, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2012 |
| Suse | — | Upgrade libopenssl-fips-providerUpgrade libqt4-x11-32bitUpgrade libqt4-sql-mysqlUpgrade libopenssl1_0_0-hmac-32bitUpgrade wgetUpgrade openssl1-docUpgrade libopenssl1_1-32bitUpgrade libqt4-qt3support-x86Upgrade libqt4-sql-postgresql-x86Upgrade openssl-1_0_0Upgrade libopenssl0_9_8-32bitUpgrade libopenssl1_0_0-32bitUpgrade libqt4-sql-32bitUpgrade libqt4-x11-x86Upgrade libqt4-devel-docUpgrade libqt4-sql-postgresqlUpgrade libqt4-sql-x86Upgrade libopenssl0_9_8Upgrade libqt4-sql-unixODBCUpgrade libopenssl1_0_0Upgrade libQtWebKit4-x86Upgrade libqt4-sql-sqlite-x86Upgrade libqt4-qt3supportUpgrade libopenssl-1_0_0-develUpgrade libqt4-sql-unixODBC-x86Upgrade libopenssl1_0_0-hmacUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade libqt4-devel-doc-dataUpgrade libopenssl-develUpgrade libqt4-sql-unixODBC-32bitUpgrade libqt4-sql-sqliteUpgrade opensslUpgrade openssl-docUpgrade libQtWebKit4Upgrade libqt4-qt3support-32bitUpgrade libqt4-linguistUpgrade libqt4-sql-sqlite-32bitUpgrade w3m-inline-imageUpgrade libQtWebKit-develUpgrade libqt4-x86Upgrade libopenssl0_9_8-x86Upgrade libqt4-32bitUpgrade libqt4-x11Upgrade libopenssl1-develUpgrade openssl1Upgrade libopenssl-1_1-develUpgrade libqt4-sql-postgresql-32bitUpgrade libopenssl0_9_8-hmacUpgrade openssl-1_0_0-docUpgrade libqt4-develUpgrade qt4-x11-toolsUpgrade wget-langUpgrade libopenssl1_1-hmacUpgrade libqt4-sql-mysql-32bitUpgrade openssl-1_1Upgrade libQtWebKit4-32bitUpgrade libopenssl1_1Upgrade libqt4-sql-mysql-x86Upgrade w3mUpgrade libopenssl0_9_8-hmac-32bitUpgrade libqt4-private-headers-develUpgrade libqt4-sqlUpgrade libqt4 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8Upgrade apache2.2-commonUpgrade libqt4-network | Nov 8, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub