Vulnerable against "CRIME" attack
Bug #1057578 reported by
Felix Geyer
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
qt4-x11 (Ubuntu) |
Fix Released
|
Undecided
|
Felix Geyer | ||
Lucid |
Fix Released
|
Undecided
|
Seth Arnold | ||
Natty |
Won't Fix
|
Undecided
|
Seth Arnold | ||
Oneiric |
Fix Released
|
Undecided
|
Seth Arnold | ||
Precise |
Fix Released
|
Undecided
|
Seth Arnold | ||
Quantal |
Fix Released
|
Undecided
|
Felix Geyer |
Bug Description
Qt(WebKit) is vulnerable against the "CRIME" attack.
Patches for Qt 4.8 and <= 4.7 have been released:
http://
Related branches
CVE References
Changed in qt4-x11 (Ubuntu Quantal): | |
assignee: | nobody → Felix Geyer (debfx) |
status: | New → In Progress |
Changed in qt4-x11 (Ubuntu Precise): | |
assignee: | nobody → Seth Arnold (seth-arnold) |
status: | New → In Progress |
Changed in qt4-x11 (Ubuntu Oneiric): | |
assignee: | nobody → Seth Arnold (seth-arnold) |
status: | New → In Progress |
Changed in qt4-x11 (Ubuntu Natty): | |
assignee: | nobody → Seth Arnold (seth-arnold) |
Changed in qt4-x11 (Ubuntu Lucid): | |
assignee: | nobody → Seth Arnold (seth-arnold) |
Changed in qt4-x11 (Ubuntu Natty): | |
status: | New → In Progress |
Changed in qt4-x11 (Ubuntu Lucid): | |
status: | New → In Progress |
Changed in qt4-x11 (Ubuntu Natty): | |
status: | In Progress → Won't Fix |
To post a comment you must log in.
This bug was fixed in the package qt4-x11 - 4:4.8.3+ dfsg-0ubuntu3
--------------- 3+dfsg- 0ubuntu3) quantal-proposed; urgency=low
qt4-x11 (4:4.8.
[ Iain Lane ]
* On armel and armhf, build with -gstabs instead of -g in an effort to get
the link step for QtWebkit to complete before timed out by the builders.
[ Felix Geyer ] SSL-compression -by-default. patch
* Disabling SSL/TLS compression to mitigate the "CRIME" attack. (LP: #1057578)
- Add disable-
-- Iain Lane <email address hidden> Tue, 02 Oct 2012 10:36:17 +0100