[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0270 -- Oracle jakarta-commons-httpclient

ID: oval:org.secpod.oval:def:1500052Date: (C)2013-03-20   (M)2023-12-07
Class: PATCHFamily: unix




Updated jakarta-commons-httpclient packages that fix one security issue arenow available for Red Hat Enterprise Linux 5 and 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System base score,which gives a detailed severity rating, is available from the CVE link inthe References section. The Jakarta Commons HttpClient component can be used to build HTTP-awareclient applications .The Jakarta Commons HttpClient component did not verify that the serverhostname matched the domain name in the subject's Common Name orsubjectAltName field in X.509 certificates. This could allow aman-in-the-middle attacker to spoof an SSL server if they had a certificatethat was valid for any domain name. All users of jakarta-commons-httpclient are advised to upgrade to theseupdated packages, which correct this issue. Applications using the JakartaCommons HttpClient component must be restarted for this update to takeeffect.

Platform:
Oracle Linux 6
Product:
jakarta-commons-httpclient
Reference:
ELSA-2013-0270
CVE-2012-5783
CVE    1
CVE-2012-5783
CPE    2
cpe:/o:oracle:linux:6
cpe:/a:apache:jakarta-commons-httpclient

© SecPod Technologies