VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2012-4929

⇱ NVD - CVE-2012-4929


  1. Vulnerabilities

CVE-2012-4929 Detail

Modified After Enrichment

This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.

Description

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.


Metrics

 
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/ CVE, MITRE
http://code.google.com/p/chromium/issues/detail?id=139744 CVE, MITRE
http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.html CVE, MITRE
http://jvn.jp/en/jp/JVN65273415/index.html CVE, MITRE
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000129.html CVE, MITRE
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html CVE, MITRE
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html CVE, MITRE
http://lists.opensuse.org/opensuse-updates/2012-10/msg00096.html CVE, MITRE
http://lists.opensuse.org/opensuse-updates/2013-01/msg00034.html CVE, MITRE
http://lists.opensuse.org/opensuse-updates/2013-01/msg00048.html CVE, MITRE
http://marc.info/?l=bugtraq&m=136612293908376&w=2 CVE, MITRE
http://news.ycombinator.com/item?id=4510829 CVE, MITRE
http://rhn.redhat.com/errata/RHSA-2013-0587.html CVE, MITRE
http://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successor CVE, MITRE
http://support.apple.com/kb/HT5784 CVE, MITRE
http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312 CVE, MITRE
http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512 CVE, MITRE
http://www.debian.org/security/2012/dsa-2579 CVE, MITRE
http://www.debian.org/security/2013/dsa-2627 CVE, MITRE
http://www.debian.org/security/2015/dsa-3253 CVE, MITRE
http://www.ekoparty.org/2012/thai-duong.php CVE, MITRE
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091 CVE, MITRE
http://www.securityfocus.com/bid/55704 CVE, MITRE
http://www.theregister.co.uk/2012/09/14/crime_tls_attack/ CVE, MITRE
http://www.ubuntu.com/usn/USN-1627-1 CVE, MITRE
http://www.ubuntu.com/usn/USN-1628-1 CVE, MITRE
http://www.ubuntu.com/usn/USN-1898-1 CVE, MITRE
https://bugzilla.redhat.com/show_bug.cgi?id=857051 CVE, MITRE
https://chromiumcodereview.appspot.com/10825183 CVE, MITRE
https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltls CVE, MITRE
https://gist.github.com/3696912 CVE, MITRE
https://github.com/mpgn/CRIME-poc CVE, MITRE
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18920 CVE, MITRE
https://threatpost.com/en_us/blogs/demo-crime-tls-attack-091212 CVE, MITRE

Weakness Enumeration

CWE-ID CWE Name Source
CWE-310 Cryptographic Issues πŸ‘ cwe source acceptance level
NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

11 change records found show changes

CVE Modified by MITRE 6/16/2026 7:45:55 PM

Action Type Old Value New Value
Added Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]


CVE Status Change 4/28/2026 9:13:23 PM

Action Type Old Value New Value

CVE Modified by CVE 11/20/2024 8:43:46 PM

Action Type Old Value New Value
Added Reference
http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/


Added Reference
http://code.google.com/p/chromium/issues/detail?id=139744


Added Reference
http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.html


Added Reference
http://jvn.jp/en/jp/JVN65273415/index.html


Added Reference
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000129.html


Added Reference
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html


Added Reference
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html


Added Reference
http://lists.opensuse.org/opensuse-updates/2012-10/msg00096.html


Added Reference
http://lists.opensuse.org/opensuse-updates/2013-01/msg00034.html


Added Reference
http://lists.opensuse.org/opensuse-updates/2013-01/msg00048.html


Added Reference
http://marc.info/?l=bugtraq&m=136612293908376&w=2


Added Reference
http://marc.info/?l=bugtraq&m=136612293908376&w=2


Added Reference
http://news.ycombinator.com/item?id=4510829


Added Reference
http://rhn.redhat.com/errata/RHSA-2013-0587.html


Added Reference
http://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successor


Added Reference
http://support.apple.com/kb/HT5784


Added Reference
http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312


Added Reference
http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512


Added Reference
http://www.debian.org/security/2012/dsa-2579


Added Reference
http://www.debian.org/security/2013/dsa-2627


Added Reference
http://www.debian.org/security/2015/dsa-3253


Added Reference
http://www.ekoparty.org/2012/thai-duong.php


Added Reference
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091


Added Reference
http://www.securityfocus.com/bid/55704


Added Reference
http://www.theregister.co.uk/2012/09/14/crime_tls_attack/


Added Reference
http://www.ubuntu.com/usn/USN-1627-1


Added Reference
http://www.ubuntu.com/usn/USN-1628-1


Added Reference
http://www.ubuntu.com/usn/USN-1898-1


Added Reference
https://bugzilla.redhat.com/show_bug.cgi?id=857051


Added Reference
https://chromiumcodereview.appspot.com/10825183


Added Reference
https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltls


Added Reference
https://gist.github.com/3696912


Added Reference
https://github.com/mpgn/CRIME-poc


Added Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18920


Added Reference
https://threatpost.com/en_us/blogs/demo-crime-tls-attack-091212


CVE Modified by MITRE 5/13/2024 10:47:20 PM

Action Type Old Value New Value

CVE Modified by MITRE 4/21/2018 9:29:00 PM

Action Type Old Value New Value
Added Reference
https://github.com/mpgn/CRIME-poc [No Types Assigned]


CVE Modified by MITRE 9/18/2017 9:35:24 PM

Action Type Old Value New Value
Added Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18920 [No Types Assigned]


Removed Reference
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18920 [No Types Assigned]


CVE Modified by MITRE 8/22/2016 10:05:44 PM

Action Type Old Value New Value
Added Reference
http://marc.info/?l=bugtraq&m=136612293908376&w=2


CVE Modified by MITRE 8/11/2016 9:59:03 PM

Action Type Old Value New Value
Added Reference
http://jvn.jp/en/jp/JVN65273415/index.html


Added Reference
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000129.html


Modified Analysis by NIST 9/01/2015 1:00:43 PM

Action Type Old Value New Value
Changed CPE Configuration
Configuration 1
 OR
 *cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
 *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*


Configuration 1
 OR
 *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
 *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Configuration 2
 OR
 *cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
 *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*


CVE Modified by MITRE 5/13/2015 9:59:27 PM

Action Type Old Value New Value
Added Reference
http://www.debian.org/security/2015/dsa-3253


Initial CVE Analysis 9/17/2012 1:57:00 PM

Action Type Old Value New Value

Quick Info

CVE Dictionary Entry:
CVE-2012-4929
NVD Published Date:
09/15/2012
NVD Last Modified:
06/16/2026
Source:
MITRE