First published: Tue Feb 19 2013(Updated: )
The Jakarta Commons HttpClient component can be used to build HTTP-aware<br>client applications (such as web browsers and web service clients).<br>The Jakarta Commons HttpClient component did not verify that the server<br>hostname matched the domain name in the subject's Common Name (CN) or<br>subjectAltName field in X.509 certificates. This could allow a<br>man-in-the-middle attacker to spoof an SSL server if they had a certificate<br>that was valid for any domain name. (CVE-2012-5783)<br>All users of jakarta-commons-httpclient are advised to upgrade to these<br>updated packages, which correct this issue. Applications using the Jakarta<br>Commons HttpClient component must be restarted for this update to take<br>effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jakarta-commons-httpclient | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-debuginfo | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-demo | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-javadoc | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-manual | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-debuginfo | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-demo | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-javadoc | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
redhat/jakarta-commons-httpclient-manual | <3.1-0.7.el6_3 | 3.1-0.7.el6_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.