TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
BID:55704
Info
TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
| Bugtraq ID: | 55704 |
| Class: | Design Error |
| CVE: |
CVE-2012-4929 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2012 12:00AM |
| Updated: | Apr 13 2015 10:16PM |
| Credit: | Juliano Rizzo and Thai Duong |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Trolltech Qt 4.6.3 Trolltech Qt 4.6.2 Trolltech Qt 4.6.1 Trolltech Qt 4.6 Trolltech Qt 4.5.2 Trolltech Qt 4.5.1 Trolltech Qt 4.4.3 Trolltech Qt 4.3.3 Trolltech Qt 4.3.2 Trolltech Qt 4.3.1 Trolltech Qt 4.3 Trolltech Qt 4.2.3 Trolltech Qt 4.2.1 Trolltech Qt 4.1.5 Trolltech Qt 4.1.4 Trolltech Qt 4.1 Trolltech Qt 4.0.1 Trolltech Qt 4.5 Trolltech Qt 4.2 Trolltech Qt 4.1 Redhat Enterprise Virtualization Hypervisor for RHEL 6 0 Redhat Enterprise Virtualization 3.3 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Mysql 5.6.10 Oracle Mysql 5.6.6 Oracle Mysql 5.6.5 Oracle Mysql 5.5.28 Oracle Mysql 5.5.27 Oracle Mysql 5.5.25 Oracle Mysql 5.5.24 Oracle Mysql 5.5.23 Oracle Mysql 5.5.19 Oracle Mysql 5.1.66 Oracle Mysql 5.1.65 Oracle Mysql 5.1.63 Oracle Mysql 5.1.62 Oracle Mysql 5.5.30 Oracle Mysql 5.1.68 Oracle Mysql 5.1.53 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Opera Software Opera Web Browser 11.52 Opera Software Opera Web Browser 11.51 Mozilla Firefox 1.5.8 Mozilla Firefox 1.5.7 Mozilla Firefox 1.5.6 Mozilla Firefox 1.5.5 Mozilla Firefox 1.5.4 Mozilla Firefox 1.5.2 Mozilla Firefox 1.5.1 Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 12 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox 0.6.1 Mozilla Firefox 0.0.13 Mozilla Firefox 15 Mozilla Firefox 14.01 Mozilla Firefox 14.0 Mozilla Firefox 14 Mozilla Firefox 13.0 Mozilla Firefox 12.0 Mozilla Firefox 11.0 Mozilla Firefox 10.0.2 Mozilla Firefox 10.0.1 Mozilla Firefox 10.0 Mozilla Firefox 10 Mozilla Firefox 1.8 Mozilla Firefox 1.5.3 Mozilla Firefox 1.5.0.9 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.11 Mozilla Firefox 1.5.0.10 Mozilla Firefox 1.5.0.1 Mozilla Firefox 1.4.1 Mozilla Firefox 0.7 Mozilla Firefox 0.6 Mozilla Firefox 0.5 Mozilla Firefox 0.4 Mozilla Firefox 0.3 Mozilla Firefox 0.2 IETF TLS 1.2 IETF TLS 1.0 IBM Storwize V7000 Unified 1.4 1 IBM Storwize V7000 Unified 1.4 0 IBM Storwize V7000 Unified 1.3.2 3 IBM Storwize V7000 Unified 1.3.2 1 IBM Storwize V7000 Unified 1.3.2 0 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Scale Out Network Attached Storage 1.3.2 1-21 IBM Scale Out Network Attached Storage 1.3.2 1-20 IBM Scale Out Network Attached Storage 1.3.2 IBM Scale Out Network Attached Storage 1.3.1 IBM Scale Out Network Attached Storage 1.3.2.3 IBM Scale Out Network Attached Storage 1.3.2.2 IBM Scale Out Network Attached Storage 1.3.0.5 IBM Scale Out Network Attached Storage 1.3.0.4 HP HP-UX B.11.31 Google Chrome 17.0.963 79 Google Chrome 17.0.963 65 Google Chrome 16.0.912 75 Google Chrome 15.0.874 102 Google Chrome 2.0.172 .43 Google Chrome 2.0.172 .37 Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 1.0.154 .61 Google Chrome 0.3.154 9 Google Chrome 0.2.149 .30 Google Chrome 0.2.149 .29 Google Chrome 0.2.149 .27 Google Chrome 21.0.1180.83 Google Chrome 21.0.1180.82 Google Chrome 21.0.1180.81 Google Chrome 21.0.1180.79 Google Chrome 21.0.1180.75 Google Chrome 21.0.1180.60 Google Chrome 21.0.1180.50 Google Chrome 21.0.1180.49 Google Chrome 20.0.1132.57 Google Chrome 20.0.1132.43 Google Chrome 20.0.1132.23 Google Chrome 2.0.172.8 Google Chrome 2.0.172.38 Google Chrome 2.0.172.28 Google Chrome 2.0.172.27 Google Chrome 2.0.172.2 Google Chrome 2.0.172 Google Chrome 2.0.170.0 Google Chrome 2.0.169.1 Google Chrome 2.0.169.0 Google Chrome 2.0.159.0 Google Chrome 2.0.158.0 Google Chrome 2.0.157.2 Google Chrome 2.0.157.0 Google Chrome 2.0.156.1 Google Chrome 19.0.1084.52 Google Chrome 19.0.1084.21 Google Chrome 19 Google Chrome 18.0.1025.168 Google Chrome 18.0.1025.162 Google Chrome 18.0.1025.151 Google Chrome 18.0.1025.142 Google Chrome 17.0.963.83 Google Chrome 17.0.963.78 Google Chrome 17.0.963.60 Google Chrome 17.0.963.56 Google Chrome 17.0.963.46 Google Chrome 16.0.912.77 Google Chrome 16.0.912.75 Google Chrome 16.0.912.63 Google Chrome 16 Google Chrome 15.0.874.121 Google Chrome 15.0.874.120 Google Chrome 14.0.835.202 Google Chrome 14.0.835.186 Google Chrome 14.0.835.163 Google Chrome 14 Google Chrome 13.0.782.215 Google Chrome 13.0.782.112 Google Chrome 13.0.782.107 Google Chrome 13 Google Chrome 12.0.742.91 Google Chrome 12.0.742.112 Google Chrome 12.0.742.100 Google Chrome 12 Google Chrome 11.0.696.77 Google Chrome 11.0.696.71 Google Chrome 11.0.696.68 Google Chrome 11.0.696.65 Google Chrome 11.0.696.57 Google Chrome 11.0.696.43 Google Chrome 11.0.672.2 Google Chrome 11 Google Chrome 10.0.648.205 Google Chrome 10.0.648.205 Google Chrome 10.0.648.204 Google Chrome 10.0.648.133 Google Chrome 10.0.648.128 Google Chrome 10.0.648.127 Google Chrome 10.0.648.127 Google Chrome 10 Google Chrome 1.0.154.65 Google Chrome 1.0.154.64 Google Chrome 1.0.154.59 Google Chrome 1.0.154.55 Google Chrome 1.0.154.53 Google Chrome 1.0.154.52 Google Chrome 1.0.154.48 Google Chrome 1.0.154.46 Google Chrome 1.0.154.43 Google Chrome 1.0.154.42 Google Chrome 1.0.154.39 Google Chrome 1.0.154.36 Google Chrome 0.4.154.33 Google Chrome 0.4.154.31 Google Chrome 0.4.154.22 Google Chrome 0.4.154.18 Google Chrome 0.3.154.3 Google Chrome 0.3.154.0 Google Chrome 0.2.153.1 Google Chrome 0.2.152.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP3 Avaya Voice Portal 5.1 SP2 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya one-X Client Enablement Services 6.0 Avaya Meeting Exchange 6.2 Avaya Meeting Exchange 6.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Conferencing Standard Edition 6.0.1 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 SP1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1.1 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 SP2 Avaya Aura Presence Services 6.1 SP1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 7.0 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Safari 5.0.6 Apple Safari 4.0.5 Apple Safari 4.0.4 Apple Safari 4.0.3 Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 5.1.4 Apple Safari 5.1.1 Apple Safari 5.1 Apple Safari 5.0.5 Apple Safari 5.0.4 Apple Safari 5.0.3 Apple Safari 5.0.2 Apple Safari 5.0.1 Apple Safari 5.0 Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Apple Safari 4 Apple Mac OS X 10.8.2 Apple Mac OS X 10.8.1 Apple Mac OS X 10.7.5 Apple Mac OS X 10.8.3 Apple Mac OS X 10.8 Apple Mac OS X 10.7.4 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X 10.7 Apple Mac OS X 10.6.8 |
| Not Vulnerable: |
Oracle Mysql 5.6.11 Oracle Mysql 5.5.31 Oracle Mysql 5.1.69 Opera Software Opera Web Browser 12.01 Mozilla Firefox 15.0.1 IBM Storwize V7000 Unified 1.4.1.0 IBM Scale Out Network Attached Storage 1.4.1.0 Google Chrome 21.0.1180.89 Digia Qt 5.0.0 Digia Qt 4.8.4 Apple Safari 6 for OSX Lion Apple Safari 5.1.7 for Windows Apple Safari 5.1.6 for OSX Lion Apple Mac OS X 10.8.4 |
Discussion
TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
TLS protocol is prone to an information-disclosure vulnerability.
A man-in-the-middle attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
TLS protocol is prone to an information-disclosure vulnerability.
A man-in-the-middle attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
Exploit / POC
TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
Attackers can use readily available tools to exploit this issue.
A proof-of-concept is available. Please see the references for more information.
Attackers can use readily available tools to exploit this issue.
A proof-of-concept is available. Please see the references for more information.
Solution / Fix
TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
-
Apple SecUpdSrvr2013-002.dmg
For Mac OS X Server v10.6.8
http://www.apple.com/support/downloads/
References
TLS Protocol CVE-2012-4929 Information Disclosure Vulnerability
References:
References:
- [Announce] SECURITY - disabling SSL/TLS compression to mitigate the "CRIME" atta (Digia)
- Details on the 'CRIME' attack (iSEC Partners)
- HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D (HP)
- Krzysztof Kotowicz�??a proof of concept code (kkotowicz)
- Multiple vulnerabilities in yaSSL (Umang_D)
- openssl security update (RHSA-2013-0587) (Avaya)
- TLS protocol information disclosure (IBM)
- [SECURITY] Fedora 16 Update: qt-4.8.2-7.fc16 (fedoraproject.org)
- About the security content of OS X Mountain Lion v10.8.4 and Security Update 201 (APPLE)
- Security Bulletin: SONAS Update Includes Fixes for Multiple Vendor Security Vuln (IBM)
- Security Bulletin: Storwize V7000 Unified Update Includes Fixes for Multiple Ven (IBM)
- The Transport Layer Security (TLS) Protocol Version 1.2 (IETF)