[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2627-1 nginx -- information leak

ID: oval:org.secpod.oval:def:600969Date: (C)2013-02-19   (M)2023-12-07
Class: PATCHFamily: unix




Juliano Rizzo and Thai Duong discovered a weakness in the TLS/SSL protocol when using compression. This side channel attack, dubbed "CRIME", allows eavesdroppers to gather information to recover the original plaintext in the protocol. This update to nginx disables SSL compression.

Platform:
Debian 6.0
Product:
nginx
Reference:
DSA-2627-1
CVE-2012-4929
CVE    1
CVE-2012-4929
CPE    2
cpe:/a:nginx:nginx
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies