CVE-2012-4929

low
Published 2012-09-15 · Modified 2026-04-29
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4929

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.2.22-12
debian debianbullseyefixed2.2.22-12
debian debianforkyfixed2.2.22-12
debian debiansidfixed2.2.22-12
debian debiantrixiefixed2.2.22-12
debian debian7.0affected
debian debian8.0affected

Application impact

VendorProductVersionsFixed
gcp googlechrome
mozillafirefox

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.