diff --git a/libs/sofia-sip/libsofia-sip-ua/tport/tport_tls.c b/libs/sofia-sip/libsofia-sip-ua/tport/tport_tls.c index 07218159db..97bc5b98ac 100644 --- a/libs/sofia-sip/libsofia-sip-ua/tport/tport_tls.c +++ b/libs/sofia-sip/libsofia-sip-ua/tport/tport_tls.c @@ -334,6 +334,8 @@ int tls_init_context(tls_t *tls, tls_issues_t const *ti) SSL_CTX_set_options(tls->ctx, SSL_OP_NO_TLSv1_2); SSL_CTX_sess_set_remove_cb(tls->ctx, NULL); SSL_CTX_set_timeout(tls->ctx, ti->timeout); + /* CRIME (CVE-2012-4929) mitigation */ + SSL_CTX_set_options(tls->ctx, SSL_OP_NO_COMPRESSION); /* Set callback if we have a passphrase */ if (ti->passphrase != NULL) {