CVE-2012-4929

Priority
Medium
Description
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google
Chrome, Qt, and other products, can encrypt compressed data without
properly obfuscating the length of the unencrypted data, which allows
man-in-the-middle attackers to obtain plaintext HTTP headers by observing
length differences during a series of guesses in which a string in an HTTP
request potentially matches an unknown string in an HTTP header, aka a
"CRIME" attack.
References
Bugs
Notes
jdstrand> Fedora/RedHat has a patch to check for OPENSSL_NO_DEFAULT_ZLIB that
can be used to mitigate this flaw. See RedHat bug #857051
jdstrand> No patch for upstream OpenSSL. This may be considered a flaw in the
applications using OpenSSL and not OpenSSL itself.
mdeslaur> adding apache2, we should backport the SSLCompression option.
mdeslaur> in trunk and 2.4, sslcompression defaults to off with a second
mdeslaur> commit. Second commit to default to off isn't in 2.2 yet.
mdeslaur> redhat disabled zlib compression by default in openssl:
mdeslaur> https://rhn.redhat.com/errata/RHSA-2013-0587.html
Package
Upstream:released (4.8.4, 5.0.0)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):released (4:4.6.2-0ubuntu5.5)
Ubuntu 11.10 (Oneiric Ocelot):released (4:4.7.4-0ubuntu8.2)
Ubuntu 12.04 LTS (Precise Pangolin):released (4:4.8.1-0ubuntu4.3)
Ubuntu 12.10 (Quantal Quetzal):released (4:4.8.3+dfsg-0ubuntu3)
Ubuntu 13.04 (Raring Ringtail):released (4:4.8.3+dfsg-0ubuntu3)
Ubuntu 13.10 (Saucy Salamander):released (4:4.8.3+dfsg-0ubuntu3)
Patches:
Upstream:http://qt.gitorious.org/qt/qt/commit/3488f1db96dbf70bb0486d3013d86252ebf433e0
Upstream:http://qt.gitorious.org/qt/qt/commit/d41dc3e101a694dec98d7bbb582d428d209e5401
Upstream:http://qt.gitorious.org/qt/qtbase/commit/5ea896fbc63593f424a7dfbb11387599c0025c74
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):needed
Ubuntu 12.10 (Quantal Quetzal):needed
Ubuntu 13.04 (Raring Ringtail):needed
Ubuntu 13.10 (Saucy Salamander):needed
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):needed
Ubuntu 11.10 (Oneiric Ocelot):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):needed
Ubuntu 12.10 (Quantal Quetzal):needed
Ubuntu 13.04 (Raring Ringtail):needed
Ubuntu 13.10 (Saucy Salamander):needed
Patches:
Vendor:http://pkgs.fedoraproject.org/cgit/openssl.git/tree/openssl-0.9.8j-env-nozlib.patch?id=1d20b5f2
Vendor:http://pkgs.fedoraproject.org/cgit/openssl.git/tree/openssl-1.0.1e-env-zlib.patch (updated)
Package
Upstream:released (2.2.22-12)
Ubuntu 8.04 LTS (Hardy Heron):released (2.2.8-1ubuntu0.24)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.2.14-5ubuntu8.10)
Ubuntu 11.10 (Oneiric Ocelot):released (2.2.20-1ubuntu1.3)
Ubuntu 12.04 LTS (Precise Pangolin):released (2.2.22-1ubuntu1.2)
Ubuntu 12.10 (Quantal Quetzal):released (2.2.22-6ubuntu2.1)
Ubuntu 13.04 (Raring Ringtail):released (2.2.22-6ubuntu3)
Ubuntu 13.10 (Saucy Salamander):released (2.2.22-6ubuntu3)
Patches:
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1345319 (trunk)
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1348656 (trunk)
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1400700 (trunk)
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1369585 (2.4)
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1400962 (2.4)
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1395231 (2.2)
Vendor:http://patch-tracker.debian.org/patch/series/view/apache2/2.2.22-12/disable-ssl-compression.patch
Package
Upstream:pending (22)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (23.0.1271.97-0ubuntu0.10.04.1)
Ubuntu 11.10 (Oneiric Ocelot):released (23.0.1271.97-0ubuntu0.11.10.1)
Ubuntu 12.04 LTS (Precise Pangolin):released (23.0.1271.97-0ubuntu0.12.04.1)
Ubuntu 12.10 (Quantal Quetzal):not-affected (22.0.1229.94~r161065-0ubuntu1)
Ubuntu 13.04 (Raring Ringtail):not-affected (22.0.1229.94~r161065-0ubuntu1)
Ubuntu 13.10 (Saucy Salamander):not-affected (22.0.1229.94~r161065-0ubuntu1)
Patches:
Upstream:https://chromiumcodereview.appspot.com/10825183
Package
Source: nss (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected (code-not-compiled)
Ubuntu 11.10 (Oneiric Ocelot):not-affected (code-not-compiled)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (code-not-compiled)
Ubuntu 12.10 (Quantal Quetzal):not-affected (code-not-compiled)
Ubuntu 13.04 (Raring Ringtail):not-affected (code-not-compiled)
Ubuntu 13.10 (Saucy Salamander):not-affected (code-not-compiled)
More Information

Valid XHTML 1.0 Strict

Updated: 2013-05-09 15:17:06 UTC (commit 6824)