The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Aug 28, 2015 | Sep 15, 2012 |
| Apple Osx Openssl | — | Apply OS X security update 2013-002Upgrade macOS to the latest version | Jun 20, 2013 | Sep 15, 2012 |
| Centos_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-staticUpgrade openssl | Dec 1, 2016 | Sep 15, 2012 |
| Debian | — | Upgrade lighttpdUpgrade nginxUpgrade apache2Upgrade poundUpgrade openssl | Jul 30, 2024 | Sep 15, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 9, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 15, 2012 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Hpux | — | Update hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest versionUpdate hpuxws22APCH32.APACHE to the latest versionUpdate hpuxws22APCH32.WEBPROXY2 to the latest version | Aug 11, 2017 | Sep 15, 2012 |
| Oracle_linux | — | Upgrade openssl-staticUpgrade opensslUpgrade openssl-develUpgrade openssl-perl | May 13, 2016 | Sep 15, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2012 |
| Suse | — | Upgrade openssl-devel-32bitUpgrade libqt4-sql-mysql-32bitUpgrade libqt4Upgrade libqt4-debuginfo-32bitUpgrade openssl-develUpgrade libqt4-qt3support-debuginfo-x86Upgrade libqt4-sql-sqlite-debuginfo-32bitUpgrade libqt4-sql-mysql-x86Upgrade libqt4-x11-debuginfoUpgrade libqt4-devel-debuginfoUpgrade libqt4-debugsourceUpgrade libopenssl-devel-32bitUpgrade libqt4-sql-debuginfoUpgrade libqt4-32bitUpgrade libqt4-develUpgrade libqt4-x86Upgrade qt4-x11-toolsUpgrade libqt4-x11-debuginfo-x86Upgrade libqt4-sqlUpgrade libqt4-x11Upgrade sle-sdk-releaseUpgrade libQtWebKit-develUpgrade libqt4-private-headers-develUpgrade libQtWebKit4-32bitUpgrade libqt4-sql-postgresql-32bitUpgrade libqt4-x11-debuginfo-32bitUpgrade openssl-64bitUpgrade libqt4-devel-doc-dataUpgrade openssl-32bitUpgrade libqt4-x11-x86Upgrade libopenssl1_0_0-32bitUpgrade libQtWebKit4Upgrade libqt4-sql-postgresqlUpgrade openssl-x86Upgrade libQtWebKit4-x86Upgrade libqt4-sql-sqlite-x86Upgrade libqt4-sql-mysqlUpgrade libqt4-sql-unixodbc-32bitUpgrade libqt4-sql-pluginsUpgrade libqt4-sql-sqlite-32bitUpgrade libqt4-sql-sqlite-debuginfoUpgrade libqt4-debuginfo-x86Upgrade libqt4-sql-32bitUpgrade libqt4-qt3supportUpgrade libqt4-qt3support-debuginfo-32bitUpgrade libqt4-sql-sqliteUpgrade libqt4-qt3support-x86Upgrade libqt4-sql-postgresql-x86Upgrade libqt4-sql-unixodbcUpgrade openssl-devel-64bitUpgrade libqt4-qt3support-debuginfoUpgrade libqt4-qt3support-32bitUpgrade libqt4-sql-unixODBC-x86Upgrade libqt4-sql-x86Upgrade libqt4-sql-debuginfo-32bitUpgrade libqt4-sql-debuginfo-x86Upgrade openssl-docUpgrade libqt4-x11-32bitUpgrade libopenssl1_0_0Upgrade libqt4-devel-docUpgrade libopenssl-develUpgrade libqt4-sql-sqlite-debuginfo-x86Upgrade opensslUpgrade libqt4-debuginfo | Dec 12, 2013 | Sep 15, 2012 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8Upgrade apache2.2-commonUpgrade libqt4-network | Nov 8, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub