Back

MEDIUM

BREACH attack against HTTP compression

Published Feb 21, 2020

Description

The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.

Affected products

Remediation

Red Hat statement

This issue is not planned to be addressed in the version of httpd as shipped with Red Hat Enterprise Linux 5 and 6. More details and possible mitigations are mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=995168#c5

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Feb 21, 2020
Updated Aug 6, 2024
Reserved May 21, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Aug 2, 2013