CVE-2012-4929

NameCVE-2012-4929
DescriptionThe TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google C ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-0008-1, DLA-400-1, DSA-2579-1, DSA-2626-1, DSA-2627-1, DSA-3253-1
Debian Bugs689936, 700399, 700426, 727197, 728055

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)bullseye2.4.62-1~deb11u1fixed
bullseye (security)2.4.66-1~deb11u1fixed
bookworm2.4.66-1~deb12u1fixed
bookworm (security)2.4.62-1~deb12u2fixed
trixie2.4.66-1~deb13u2fixed
forky, sid2.4.66-8fixed
lighttpd (PTS)bullseye (security), bullseye1.4.59-1+deb11u2fixed
bookworm1.4.69-1fixed
trixie1.4.79-2fixed
forky, sid1.4.82-2fixed
nginx (PTS)bullseye1.18.0-6.1+deb11u3fixed
bullseye (security)1.18.0-6.1+deb11u5fixed
bookworm1.22.1-9+deb12u3fixed
bookworm (security)1.22.1-9+deb12u4fixed
trixie (security), trixie1.26.3-3+deb13u2fixed
forky, sid1.30.0-2fixed
openssl (PTS)bullseye1.1.1w-0+deb11u1fixed
bullseye (security)1.1.1w-0+deb11u5fixed
bookworm3.0.18-1~deb12u1fixed
bookworm (security)3.0.19-1~deb12u2fixed
trixie3.5.5-1~deb13u1fixed
trixie (security)3.5.5-1~deb13u2fixed
forky, sid3.6.2-1fixed
pound (PTS)bullseye3.0-2fixed
trixie4.16-3fixed
forky, sid4.22-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2sourcesqueeze2.2.16-6+squeeze10DSA-2579-1
apache2source(unstable)2.2.22-12689936
chromium-browsersourcesqueeze(unfixed)end-of-life
chromium-browsersource(unstable)22.0.1229.94~r161065-1
iceweaselsource(unstable)(not affected)
lighttpdsourcesqueeze1.4.28-2+squeeze1.2DSA-2626-1
lighttpdsource(unstable)1.4.30-1700399
nginxsourcesqueeze0.7.67-3+squeeze3DSA-2627-1
nginxsource(unstable)1.2.1-2.2700426
opensslsourcesqueeze0.9.8o-4squeeze16
opensslsourcewheezy1.0.1e-2+deb7u11
opensslsource(unstable)1.0.1e-5low728055
poundsourcesqueeze2.6-1+deb6u1DLA-400-1
poundsourcewheezy2.6-2+deb7u1DSA-3253-1
poundsourcejessie2.6-6+deb8u1DSA-3253-1
poundsource(unstable)2.6-3727197
qt4-x11source(unstable)4:4.8.2+dfsg-3

Notes

- iceweasel <not-affected> (Firefox ESV not use TLS/SSL compression)
Chromium fix: https://chromiumcodereview.appspot.com/10825183/
[squeeze] - qt4-x11 <no-dsa> (Minor issue)
openssl redhat announcement https://rhn.redhat.com/errata/RHSA-2013-0587.html
openssl disables compression by default since dc5744cb78da6f2bcafeeefe22c604a51b52dfc5

Search for package or bug name: Reporting problems