disable ssl compression to mitigate the BEAST attack

Bug #1073603 reported by seph
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apache2 (Ubuntu)
New
Undecided
Unassigned

Bug Description

Apache 2.2 is vulnerable to the CRIME attack. While modern browsers are not vulnerable to this. older browsers are. And various compliance scans will check for it.

Apache's bug report -- https://issues.apache.org/bugzilla/show_bug.cgi?id=53219

seph (seph)
information type: Private Security → Public Security
Revision history for this message
Robie Basak (racb) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1068854, so it is being marked as such. Please look at the other bug report to see if there is any missing information that you can provide, or to see if there is a workaround for the bug. Additionally, any further discussion regarding the bug should occur in the other report. Feel free to continue to report any other bugs you may find.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.