| Reference | Source | Link | Tags |
|---|
| JVN#65273415: Android OS issue where it is affected by the CRIME attack |
JVN |
jvn.jp |
|
| '[security bulletin] HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D' - MARC |
HP |
marc.info |
|
| GitHub - mpgn/CRIME-poc: CRIME attack PoC : a compression oracle attacks CVE-2012-4929 |
MISC |
github.com |
|
| Debian -- Security Information -- DSA-3253-1 pound |
DEBIAN |
www.debian.org |
|
| Bug 857051 – CVE-2012-4929 SSL/TLS CRIME attack against HTTPS |
CONFIRM |
bugzilla.redhat.com |
|
| Issue 10825183: net: disable TLS compression with OpenSSL. -
Code Review |
CONFIRM |
chromiumcodereview.appspot.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| The perfect CRIME? New HTTPS web hijack attack explained • The Register |
MISC |
www.theregister.co.uk |
|
| ssl - CRIME - How to beat the BEAST successor? - IT Security |
MISC |
security.stackexchange.com |
|
| New Attack Uses SSL/TLS Information Leak to Hijack HTTPS Sessions | threatpost |
MISC |
threatpost.com |
|
| [SECURITY] Fedora 18 Update: mingw-openssl-1.0.1e-1.fc18 |
FEDORA |
lists.fedoraproject.org |
|
| TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
|
| Debian -- Security Information -- DSA-2627-1 nginx |
DEBIAN |
www.debian.org |
|
| USN-1628-1: Qt vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| It's not a crime to build a CRIME |
MISC |
gist.github.com |
|
| Compression and Information Leakage of Plaintext |
MISC |
www.iacr.org |
|
| JVNDB-2016-000129 - JVN iPedia |
JVNDB |
jvndb.jvn.jp |
|
| Repository / Oval Repository |
OVAL |
oval.cisecurity.org |
|
| openSUSE-SU-2013:0157-1: moderate: libqt4: security fixes for XMLHttpReq |
SUSE |
lists.opensuse.org |
|
| ekoparty Security Conference |
MISC |
www.ekoparty.org |
|
| Google disables compression for OpenSSL in Chrome - SSL exploit coming? | Hacker News |
MISC |
news.ycombinator.com |
|
| openSUSE-SU-2013:0143-1: moderate: libqt4: security fixes for XMLHttpReq |
SUSE |
lists.opensuse.org |
|
| Details on the “CRIME” attack - Blog - iSEC Partners |
MISC |
isecpartners.com |
|
| APPLE-SA-2013-06-04-1 OS X Mountain Lion v10.8.4 and Security Update 2013-002 |
APPLE |
lists.apple.com |
|
| 139744 -
chromium -
An open-source project to help move the web forward. -
Monorail |
CONFIRM |
code.google.com |
|
| Demo of the CRIME TLS Attack | threatpost |
MISC |
threatpost.com |
|
| CRIME: Information Leakage Attack against SSL/TLS | Qualys Security Labs | Qualys Community |
MISC |
community.qualys.com |
|
| USN-1898-1: OpenSSL vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Debian -- Security Information -- DSA-2579-1 apache2 |
DEBIAN |
www.debian.org |
|
| Crack in Internet’s foundation of trust allows HTTPS session hijacking | Ars Technica |
MISC |
arstechnica.com |
|
| About the security content of OS X Mountain Lion v10.8.4 and Security Update 2013-002 |
CONFIRM |
support.apple.com |
|
| openSUSE-SU-2012:1420-1: moderate: update for libqt4 |
SUSE |
lists.opensuse.org |
|
| CRIME Attack Uses Compression Ratio of TLS Requests as Side Channel to Hijack Secure Sessions | threatpost |
MISC |
threatpost.com |
|
| USN-1627-1: Apache HTTP Server vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |