Oval Definition:oval:com.redhat.rhsa:def:20130270
Revision Date:2013-02-19Version:636
Title:RHSA-2013:0270: jakarta-commons-httpclient security update (Moderate)
Description:The Jakarta Commons HttpClient component can be used to build HTTP-aware client applications (such as web browsers and web service clients).

  • The Jakarta Commons HttpClient component did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name. (CVE-2012-5783)

    All users of jakarta-commons-httpclient are advised to upgrade to these updated packages, which correct this issue. Applications using the Jakarta Commons HttpClient component must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-5783
    CVE-2012-5783
    RHSA-2013:0270
    RHSA-2013:0270-02
    RHSA-2013:0270-02
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3
  • AND jakarta-commons-httpclient is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3
  • AND jakarta-commons-httpclient-demo is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3
  • AND jakarta-commons-httpclient-javadoc is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3
  • AND jakarta-commons-httpclient-manual is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2
  • AND jakarta-commons-httpclient is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2
  • AND jakarta-commons-httpclient-demo is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2
  • AND jakarta-commons-httpclient-javadoc is signed with Red Hat redhatrelease2 key
  • jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2
  • AND jakarta-commons-httpclient-manual is signed with Red Hat redhatrelease2 key
  • BACK