Re: nginx 1.2.1-2.2~bpo+60.1 and CVE-2012-4929 (CRIME attack)
Le 2013-02-25 11:11, Apollon Oikonomopoulos a écrit :
The version of nginx currently in squeeze-backports
seems to have SSL compression enabled and is vulnerable to the CRIME
attack (CVE-2012-4929 - see). The same version in wheezy is *not*
vulnerable because it links against libssl1.0.0 which has SSL
compression disabled by default. The backport however links against
libssl0.9.8 and has SSL compression enabled by default, and thus the
patch attached in  must be applied.
I'm going to perform this backport in the next days (maybe tonight),
but I haven't had enough time.
By the way, how do I need to call this version ?, 1.2.1-2.2~bpo+60+1.1
Cyril "Davromaniak" Lavier