Mozilla Foundation Security Advisory 2012-73
SPDY information disclosure
- Announced
- September 21, 2012
- Reporter
- Thai Duong, Juliano Rizzo
- Impact
- High
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 15
- SeaMonkey 2.12
Description
Security researchers Thai Duong and Juliano Rizzo reported that SPDY's request header compression leads to information leakage, which can allow the extraction of private data such as session cookies, even over an encrypted SSL connection.