Oval Definition:oval:org.mitre.oval:def:26509
Revision Date:2014-11-17Version:8
Title:ELSA-2014-1146 -- httpcomponents-client security update (Important)
Description:HttpClient is an HTTP/1.1 compliant HTTP agent implementation based onhttpcomponents HttpCore.It was discovered that the HttpClient incorrectly extracted host name froman X.509 certificate subject's Common Name (CN) field. A man-in-the-middleattacker could use this flaw to spoof an SSL server using a speciallycrafted X.509 certificate. (CVE-2014-3577)For additional information on this flaw, refer to the Knowledgebasearticle in the References section.All httpcomponents-client users are advised to upgrade to these updatedpackages, which contain a backported patch to correct this issue.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-6153
CVE-2014-3577
ELSA-2014-1146
Platform(s):Oracle Linux 7
Product(s):httpcomponents-client
Definition Synopsis
  • Oracle Linux 7.x
  • AND Packages match section
  • httpcomponents-client RPM is earlier than 0:4.2.5-5.el7_0
  • OR httpcomponents-client-javadoc RPM is earlier than 0:4.2.5-5.el7_0
  • BACK