The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Apply OS X security update 2013-002Upgrade macOS to the latest version | Aug 28, 2015 | Sep 15, 2012 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Jun 20, 2013 | Sep 15, 2012 |
| Centos_linux | — | Upgrade opensslUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-perl | Dec 1, 2016 | Sep 15, 2012 |
| Debian | — | Upgrade lighttpdUpgrade nginxUpgrade opensslUpgrade apache2Upgrade pound | Jul 30, 2024 | Sep 15, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 9, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 15, 2012 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Hpux | — | Update hpuxws22APCH32.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest versionUpdate hpuxws22APCH32.APACHE to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest version | Aug 11, 2017 | Sep 15, 2012 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade openssl-develUpgrade opensslUpgrade openssl-static | May 13, 2016 | Sep 15, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2012 |
| Suse | — | Upgrade libqt4-sql-postgresql-32bitUpgrade openssl-1_1Upgrade libopenssl-1_1-develUpgrade libopenssl1-develUpgrade libqt4-develUpgrade libopenssl1_1-hmacUpgrade libQtWebKit4-32bitUpgrade libqt4-sql-mysql-32bitUpgrade qt4-x11-toolsUpgrade libqt4-x11Upgrade wget-langUpgrade openssl-1_0_0-docUpgrade libqt4-sqlUpgrade libqt4Upgrade libqt4-x86Upgrade libqt4-sql-mysql-x86Upgrade openssl1Upgrade libopenssl0_9_8-x86Upgrade w3m-inline-imageUpgrade libopenssl0_9_8-hmac-32bitUpgrade libQtWebKit-develUpgrade libopenssl1_1Upgrade libqt4-32bitUpgrade w3mUpgrade libqt4-private-headers-develUpgrade libopenssl0_9_8-hmacUpgrade libqt4-x11-32bitUpgrade libqt4-devel-doc-dataUpgrade libqt4-qt3support-x86Upgrade opensslUpgrade openssl1-docUpgrade libqt4-linguistUpgrade libqt4-sql-postgresql-x86Upgrade libopenssl1_1-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0-hmacUpgrade libqt4-sql-mysqlUpgrade libqt4-sql-sqlite-x86Upgrade libopenssl0_9_8-32bitUpgrade libqt4-sql-unixODBC-32bitUpgrade libqt4-sql-sqlite-32bitUpgrade libqt4-devel-docUpgrade wgetUpgrade openssl-docUpgrade libopenssl-develUpgrade libopenssl-1_1-devel-32bitUpgrade libQtWebKit4-x86Upgrade libopenssl-1_0_0-develUpgrade openssl-1_0_0Upgrade libqt4-x11-x86Upgrade libqt4-sql-postgresqlUpgrade libopenssl-fips-providerUpgrade libopenssl1_0_0-32bitUpgrade libqt4-sql-sqliteUpgrade libqt4-sql-unixODBCUpgrade libQtWebKit4Upgrade libopenssl1_0_0Upgrade libopenssl0_9_8Upgrade libqt4-sql-unixODBC-x86Upgrade libqt4-sql-32bitUpgrade libqt4-qt3supportUpgrade libqt4-qt3support-32bitUpgrade libqt4-sql-x86 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8Upgrade apache2.2-commonUpgrade libqt4-network | Nov 8, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub