ELSA-2013-0270 -- Oracle jakarta-commons-httpclientID: oval:org.secpod.oval:def:1500052 | Date: (C)2013-03-20 (M)2023-12-07 |
Class: PATCH | Family: unix |
Updated jakarta-commons-httpclient packages that fix one security issue arenow available for Red Hat Enterprise Linux 5 and 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System base score,which gives a detailed severity rating, is available from the CVE link inthe References section. The Jakarta Commons HttpClient component can be used to build HTTP-awareclient applications .The Jakarta Commons HttpClient component did not verify that the serverhostname matched the domain name in the subject's Common Name orsubjectAltName field in X.509 certificates. This could allow aman-in-the-middle attacker to spoof an SSL server if they had a certificatethat was valid for any domain name. All users of jakarta-commons-httpclient are advised to upgrade to theseupdated packages, which correct this issue. Applications using the JakartaCommons HttpClient component must be restarted for this update to takeeffect.
Product: |
jakarta-commons-httpclient |