CVE-2012-4929
nginx - information leak
EPSS 4.3%
描述
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
如何修補 CVE-2012-4929
要修補 CVE-2012-4929,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.22-12 或更新版本
- —升級至 1.4.30-1 或更新版本
- —升級至 1.2.1-2.2 或更新版本
- —升級至 0.7.67-3+squeeze3 或更新版本
- —升級至 1.0.1e-5 或更新版本
- —升級至 0.9.8o-4squeeze16 或更新版本
- —升級至 2.6-3 或更新版本
CVE-2012-4929 正在被利用嗎?
低 — EPSS 為 4.3%,目前沒有觀察到大規模利用活動。
受影響套件(7)
- from 0, < 2.2.22-12
- from 0, < 1.4.30-1
- from 0, < 1.2.1-2.2
- from 0, < 0.7.67-3+squeeze3
- from 0, < 1.0.1e-5
- from 0, < 0.9.8o-4squeeze16
- from 0, < 2.6-3