You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2012-73

Mozilla Foundation Security Advisory 2012-73

Title: SPDY information disclosure
Impact: High
Announced: September 21, 2012
Reporter: Thai Duong, Juliano Rizzo
Products: Firefox, SeaMonkey

Fixed in: Firefox 15
  SeaMonkey 2.12

Description

Security researchers Thai Duong and Juliano Rizzo reported that SPDY's request header compression leads to information leakage, which can allow the extraction of private data such as session cookies, even over an encrypted SSL connection.

References