First published: Mon Mar 25 2013(Updated: )
The Jakarta Commons HttpClient component can be used to build HTTP-aware<br>client applications (such as web browsers and web service clients).<br>The Jakarta Commons HttpClient component did not verify that the server<br>hostname matched the domain name in the subject's Common Name (CN) or<br>subjectAltName field in X.509 certificates. This could allow a<br>man-in-the-middle attacker to spoof an SSL server if they had a certificate<br>that was valid for any domain name. (CVE-2012-5783)<br>Warning: Before applying this update, back up your existing JBoss<br>Enterprise Web Platform installation (including all applications and<br>configuration files).<br>All users of JBoss Enterprise Web Platform 5.2.0 on Red Hat Enterprise<br>Linux 4, 5, and 6 are advised to upgrade to this updated package. The JBoss<br>server process must be restarted for the update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jakarta-commons-httpclient | <3.1-2_patch_01.ep5.el6 | 3.1-2_patch_01.ep5.el6 |
redhat/jakarta-commons-httpclient | <3.1-2_patch_01.ep5.el6 | 3.1-2_patch_01.ep5.el6 |
redhat/jakarta-commons-httpclient | <3.1-2.1_patch_01.ep5.el5 | 3.1-2.1_patch_01.ep5.el5 |
redhat/jakarta-commons-httpclient | <3.1-2.1_patch_01.ep5.el5 | 3.1-2.1_patch_01.ep5.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2013:0682 is classified as moderate.
To fix RHSA-2013:0682, you should update to jakarta-commons-httpclient version 3.1-2_patch_01.ep5.el6 or 3.1-2.1_patch_01.ep5.el5.
RHSA-2013:0682 affects systems running jakarta-commons-httpclient versions prior to 3.1-2_patch_01.ep5.el6 and 3.1-2.1_patch_01.ep5.el5.
The issue in RHSA-2013:0682 relates to the Jakarta Commons HttpClient component not properly verifying that the server hostname matches the domain name.
There is no official workaround for RHSA-2013:0682; the recommended action is to apply the security patch.