CVE-2012-4929
published 2012-09-15CVE-2012-4929: The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating…
PriorityP415low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
4.27%
90.0th percentile
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apsis | pound | >= 0 < 2.6-3 | 2.6-3 |
| apsis | pound | >= 0 < 2.6-3 | 2.6-3 |
| apsis | pound | >= 0 < 2.6-3 | 2.6-3 |
| debian | apache2 | < apache2 2.2.22-12 (bookworm) | apache2 2.2.22-12 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lighttpd | < apache2 2.2.22-12 (bookworm) | apache2 2.2.22-12 (bookworm) |
| debian | nginx | < apache2 2.2.22-12 (bookworm) | apache2 2.2.22-12 (bookworm) |
| debian | openssl | < apache2 2.2.22-12 (bookworm) | apache2 2.2.22-12 (bookworm) |
| debian | pound | < apache2 2.2.22-12 (bookworm) | apache2 2.2.22-12 (bookworm) |
| f5 | arx | 5.0.0 – 5.3.1 | — |
| f5 | arx | 6.0.0 – 6.4.0 | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_access_policy_manager | 11.0.0 – 11.6.1 | — |
| f5 | big-ip_access_policy_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.3.0 – 11.6.1 | — |
| f5 | big-ip_advanced_firewall_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.0.0 – 11.6.1 | — |
| f5 | big-ip_analytics | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.4.0 – 11.6.1 | — |
| f5 | big-ip_application_acceleration_manager | 12.0.0 – 12.1.2 | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-348j-44v2-vwfr: The TLS protocol 1
ghsa_unreviewed·2022-05-14
CVE-2012-4929 [LOW] GHSA-348j-44v2-vwfr: The TLS protocol 1
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
GHSA
GHSA-hh3m-fgxm-fq25: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da
ghsa_unreviewed·2022-05-05·CVSS 2.6
CVE-2013-3587 [LOW] CWE-200 GHSA-hh3m-fgxm-fq25: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
OSV
CVE-2012-4929: The TLS protocol 1
osv·2012-09-15·CVSS 2.6
CVE-2012-4929 [LOW] CVE-2012-4929: The TLS protocol 1
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Red Hat
BREACH attack against HTTP compression
vendor_redhat·2013-08-02·CVSS 2.6
CVE-2013-3587 [LOW] BREACH attack against HTTP compression
BREACH attack against HTTP compression
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
Statement: This issue is not planned to be addressed in the version of httpd as shipped with Red Hat Enterprise Linux 5 and 6. More details and possible mitigations are mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=995168#c5
Package: httpd (Red Hat Enterprise Linux 5) - Will not
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2013-07-04
CVE-2012-4929 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: Applications could be made to expose sensitive information over the
network.
The TLS protocol 1.2 and earlier can encrypt compressed data without
properly obfuscating the length of the unencrypted data, which allows
machine-in-the-middle attackers to obtain plaintext content by observing
length differences during a series of guesses in which a provided string
potentially matches an unknown string in encrypted and compressed traffic.
This is known as a CRIME attack in HTTP. Other protocols layered on top of
TLS may also make these attacks practical.
This update disables compression for all programs using SSL and TLS
provided by the OpenSSL library. To re-enable compression for programs
that need compression to communicate with legacy services, define
Ubuntu
Qt vulnerability
vendor_ubuntu·2012-11-08
CVE-2012-4929 Qt vulnerability
Title: Qt vulnerability
Summary: Qt applications could be made to expose sensitive information over
the network.
Juliano Rizzo and Thai Duong discovered a flaw in the Transport Layer
Security (TLS) protocol when it is used with data compression. If an
attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. This update disables
TLS data compression in Qt by default.
Instructions: After a standard system update you need to restart any KDE sessions or
applications linked against Qt to make all the necessary changes.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2012-11-08·CVSS 2.6
CVE-2012-2687 [LOW] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in the Apache HTTP server.
It was discovered that the mod_negotiation module incorrectly handled
certain filenames, which could result in browsers becoming vulnerable to
cross-site scripting attacks when processing the output. With cross-site
scripting vulnerabilities, if a user were tricked into viewing server
output during a crafted server request, a remote attacker could exploit
this to modify the contents, or steal confidential data (such as
passwords), within the same domain. (CVE-2012-2687)
It was discovered that the Apache HTTP Server was vulnerable to the "CRIME"
SSL data compression attack. Although this issue had been mitigated on the
client with newer web browsers, this update also disables
Red Hat
SSL/TLS CRIME attack against HTTPS
vendor_redhat·2012-09-13·CVSS 2.6
CVE-2012-4929 [LOW] SSL/TLS CRIME attack against HTTPS
SSL/TLS CRIME attack against HTTPS
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
Package: gnutls (Red Hat Enterprise Linux 4) - Will not fix
Package: nss (Red Hat Enterprise Linux 4) - Not affected
Package: openssl (Red Hat Enterprise Linux 4) - Not affected
Package: gnutls (Red Hat Enterprise Linux 5) - Will not fix
Package: nss (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a
Debian
CVE-2012-4929: apache2 - The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt,...
vendor_debian·2012·CVSS 2.6
CVE-2012-4929 [LOW] CVE-2012-4929: apache2 - The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt,...
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
Scope: local
bookworm: resolved (fixed in 2.2.22-12)
bullseye: resolved (fixed in 2.2.22-12)
forky: resolved (fixed in 2.2.22-12)
sid: resolved (fixed in 2.2.22-12)
trixie: resolved (fixed in 2.2.22-12)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0169 CVE-2012-4929 mingw32-openssl various flaws [epel-5]
bugzilla·2013-03-12·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 CVE-2012-4929 mingw32-openssl various flaws [epel-5]
CVE-2013-0169 CVE-2012-4929 mingw32-openssl various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mingw32-o
Bugzilla
CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
bugzilla·2013-03-12·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issu
Bugzilla
CVE-2012-4929 SSL/TLS CRIME attack against HTTPS [fedora-all]
bugzilla·2012-12-11·CVSS 2.6
CVE-2012-4929 [LOW] CVE-2012-4929 SSL/TLS CRIME attack against HTTPS [fedora-all]
CVE-2012-4929 SSL/TLS CRIME attack against HTTPS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple su
Bugzilla
CVE-2012-4930 SPDY: SSL/TLS CRIME attack
bugzilla·2012-09-16·CVSS 2.6
CVE-2012-4930 [LOW] CVE-2012-4930 SPDY: SSL/TLS CRIME attack
CVE-2012-4930 SPDY: SSL/TLS CRIME attack
CVE-2012-4930 was assigned to the following issue:
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown
string in an HTTP header, aka a "CRIME" attack.
References:
http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/
http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.html
http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channe
Bugzilla
CVE-2012-4929 SSL/TLS CRIME attack against HTTPS
bugzilla·2012-09-13·CVSS 2.6
CVE-2012-4929 [LOW] CVE-2012-4929 SSL/TLS CRIME attack against HTTPS
CVE-2012-4929 SSL/TLS CRIME attack against HTTPS
Juliano Rizzo and Thai Duong, researches that reported BEAST (Browser Exploit Against SSL/TLS, bug #737506) attack announced they are planning to disclose another attack against SSL/TLS named CRIME. The issue is planned to be presented by them on the ekoparty 2012 conference.
http://www.ekoparty.org/2012/juliano-rizzo.php
http://www.ekoparty.org/2012/thai-duong.php
http://www.h-online.com/security/news/item/BEAST-creators-develop-new-SSL-attack-1702136.html
http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512
Discussion:
After the announcement of the upcoming presentation of CRIME, researches started to investigate what the issue used by CRIME may be, resulting in publication attack takin
RFC
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
rfc·2023-09-01
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Internet Engineering Task Force (IETF) D. Fett
Request for Comments: 9449 Authlete
Category: Standards Track B. Campbell
ISSN: 2070-1721 Ping Identity
J. Bradley
Yubico
T. Lodderstedt
Tuconic
M. Jones
Self-Issued Consulting
D. Waite
Ping Identity
September 2023
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Abstract
This document describes a mechanism for sender-constraining OAuth 2.0
tokens via a proof-of-possession mechanism on the application level.
This mechanism allows for the detection of replay attacks with access
and refresh tokens.
Status of This Memo
This is an Internet Standards Track document.
This document is a product of the Internet Engineering Task Force
(IETF). It represents the consensus of the IETF community. It has
received public review and has been appr
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
RFC
Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)
rfc·2015-02-01
Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)
Internet Engineering Task Force (IETF) Y. Sheffer
Request for Comments: 7457 Porticor
Category: Informational R. Holz
ISSN: 2070-1721 Technische Universitaet Muenchen
P. Saint-Andre
&yet
February 2015
Summarizing Known Attacks on Transport Layer Security (TLS)
and Datagram TLS (DTLS)
Abstract
Over the last few years, there have been several serious attacks on
Transport Layer Security (TLS), including attacks on its most
commonly used ciphers and modes of operation. This document
summarizes these attacks, with the goal of motivating generic and
protocol-specific recommendations on the usage of TLS and Datagram
TLS (DTLS).
Status of This Memo
This document is not an Internet Standards Track specification; it is
published for informational purposes.
This document is a product of the In
Crowdstrike
The Risks of Expired SSL Certificates Explained
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] The Risks of Expired SSL Certificates Explained
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/http://code.google.com/p/chromium/issues/detail?id=139744http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.htmlhttp://jvn.jp/en/jp/JVN65273415/index.htmlhttp://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000129.htmlhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00096.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00048.htmlhttp://marc.info/?l=bugtraq&m=136612293908376&w=2http://news.ycombinator.com/item?id=4510829http://rhn.redhat.com/errata/RHSA-2013-0587.htmlhttp://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successorhttp://support.apple.com/kb/HT5784http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512http://www.debian.org/security/2012/dsa-2579http://www.debian.org/security/2013/dsa-2627http://www.debian.org/security/2015/dsa-3253http://www.ekoparty.org/2012/thai-duong.phphttp://www.iacr.org/cryptodb/data/paper.php?pubkey=3091http://www.securityfocus.com/bid/55704http://www.theregister.co.uk/2012/09/14/crime_tls_attack/http://www.ubuntu.com/usn/USN-1627-1http://www.ubuntu.com/usn/USN-1628-1http://www.ubuntu.com/usn/USN-1898-1https://bugzilla.redhat.com/show_bug.cgi?id=857051https://chromiumcodereview.appspot.com/10825183https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltlshttps://gist.github.com/3696912https://github.com/mpgn/CRIME-pochttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18920https://threatpost.com/en_us/blogs/demo-crime-tls-attack-091212http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/http://code.google.com/p/chromium/issues/detail?id=139744http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.htmlhttp://jvn.jp/en/jp/JVN65273415/index.htmlhttp://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000129.htmlhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00096.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00048.htmlhttp://marc.info/?l=bugtraq&m=136612293908376&w=2http://news.ycombinator.com/item?id=4510829http://rhn.redhat.com/errata/RHSA-2013-0587.htmlhttp://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successorhttp://support.apple.com/kb/HT5784http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512http://www.debian.org/security/2012/dsa-2579http://www.debian.org/security/2013/dsa-2627http://www.debian.org/security/2015/dsa-3253http://www.ekoparty.org/2012/thai-duong.phphttp://www.iacr.org/cryptodb/data/paper.php?pubkey=3091http://www.securityfocus.com/bid/55704http://www.theregister.co.uk/2012/09/14/crime_tls_attack/http://www.ubuntu.com/usn/USN-1627-1http://www.ubuntu.com/usn/USN-1628-1http://www.ubuntu.com/usn/USN-1898-1https://bugzilla.redhat.com/show_bug.cgi?id=857051https://chromiumcodereview.appspot.com/10825183https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltlshttps://gist.github.com/3696912https://github.com/mpgn/CRIME-pochttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18920https://threatpost.com/en_us/blogs/demo-crime-tls-attack-091212
2012-09-15
Published