---
title: "CVE-2012-4930\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-4930?format=md
keywords: index, follow
---

# CVE-2012-4930

Publication date 15 September 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome,
and other products, can perform TLS encryption of compressed data without
properly obfuscating the length of the unencrypted data, which allows
man-in-the-middle attackers to obtain plaintext HTTP headers by observing
length differences during a series of guesses in which a string in an HTTP
request potentially matches an unknown string in an HTTP header, aka a
"CRIME" attack.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-4930?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 12.10 quantal | Not affected |
| 12.04 LTS precise | Fixed 23.0.1271.97-0ubuntu0.12.04.1 |
| 11.10 oneiric | Fixed 23.0.1271.97-0ubuntu0.11.10.1 |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Fixed 23.0.1271.97-0ubuntu0.10.04.1 |
| 8.04 LTS hardy | Not in release |
| firefox | 12.10 quantal | Fixed 15.0+build1-0ubuntu1 |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Ignored end of life |
| openssl | 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2012-4930?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

Firefox 15 disables compression
For SPDY to be used with OpenSSL in any way, NPN must be available
in openssl. This was not introduced until 1.0.1. No patch for upstream
OpenSSL. This may be considered a flaw in the applications using OpenSSL and
not OpenSSL itself.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openssl | * Vendor:   <http://pkgs.fedoraproject.org/cgit/openssl.git/tree/openssl-0.9.8j-env-nozlib.patch?id=1d20b5f2> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4930)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-4930)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-4930)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-4930)

### Other references

* <https://community.qualys.com/blogs/securitylabs/2012/09/14/crime-information-leakage-attack-against-ssltls>
* <https://bugzilla.redhat.com/show_bug.cgi?id=857737>
* <http://www.theregister.co.uk/2012/09/14/crime_tls_attack/>
* <http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091>
* <http://www.ekoparty.org/2012/thai-duong.php>
* <http://threatpost.com/en_us/blogs/crime-attack-uses-compression-ratio-tls-requests-side-channel-hijack-secure-sessions-091312>
* <http://isecpartners.com/blog/2012/9/14/details-on-the-crime-attack.html>
* <http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/>
* <https://www.cve.org/CVERecord?id=CVE-2012-4930>
