Moderate CentOS jakarta-commons-httpclient Update

Metadata

medium
5.8
jakarta-commons-httpclient-3.0-7jpp.2.i386.rpm, jakarta-commons-httpclient-3.0-7jpp.2.src.rpm, jakarta-commons-httpclient-3.0-7jpp.2.x86_64.rpm, jakarta-commons-httpclient-demo-3.0-7jpp.2.i386.rpm, jakarta-commons-httpclient-demo-3.0-7jpp.2.x86_64.rpm, jakarta-commons-httpclient-javadoc-3.0-7jpp.2.i386.rpm, jakarta-commons-httpclient-javadoc-3.0-7jpp.2.x86_64.rpm, jakarta-commons-httpclient-manual-3.0-7jpp.2.i386.rpm, jakarta-commons-httpclient-manual-3.0-7jpp.2.x86_64.rpm
CVE-2012-5783
rhn.redhat.com, lists.centos.org
2013-02-20
2017-07-27 19:04
ALAS-2013-169
ALAS-2014-410
CVE-2012-5783 commons-httpclient
CVE-2012-5783
2017-04-01 19:06
2017-01-05 20:10

Description


Updated jakarta-commons-httpclient packages that fix one security issue are
now available for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

The Jakarta Commons HttpClient component can be used to build HTTP-aware
client applications (such as web browsers and web service clients).

The Jakarta Commons HttpClient component did not verify that the server
hostname matched the domain name in the subject's Common Name (CN) or
subjectAltName field in X.509 certificates. This could allow a
man-in-the-middle attacker to spoof an SSL server if they had a certificate
that was valid for any domain name. (CVE-2012-5783)

All users of jakarta-commons-httpclient are advised to upgrade to these
updated packages, which correct this issue. Applications using the Jakarta
Commons HttpClient component must be restarted for this update to take
effect.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
unknown jakarta-commons-httpclient jakarta-commons-httpclient-3.0-7jpp.2.i386.rpm
jakarta-commons-httpclient jakarta-commons-httpclient-3.0-7jpp.2.src.rpm
jakarta-commons-httpclient jakarta-commons-httpclient-3.0-7jpp.2.x86_64.rpm
jakarta-commons-httpclient-demo jakarta-commons-httpclient-demo-3.0-7jpp.2.i386.rpm
jakarta-commons-httpclient-demo jakarta-commons-httpclient-demo-3.0-7jpp.2.x86_64.rpm
jakarta-commons-httpclient-javadoc jakarta-commons-httpclient-javadoc-3.0-7jpp.2.i386.rpm
jakarta-commons-httpclient-javadoc jakarta-commons-httpclient-javadoc-3.0-7jpp.2.x86_64.rpm
jakarta-commons-httpclient-manual jakarta-commons-httpclient-manual-3.0-7jpp.2.i386.rpm
jakarta-commons-httpclient-manual jakarta-commons-httpclient-manual-3.0-7jpp.2.x86_64.rpm