SPDY information disclosure

Related Vulnerabilities: CVE-2012-4930  

Mozilla Foundation Security Advisory 2012-73

SPDY information disclosure

Announced
September 21, 2012
Reporter
Thai Duong, Juliano Rizzo
Impact
High
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 15
  • SeaMonkey 2.12

Description

Security researchers Thai Duong and Juliano Rizzo reported that SPDY's request header compression leads to information leakage, which can allow the extraction of private data such as session cookies, even over an encrypted SSL connection.

References