Oval Definition:oval:org.opensuse.security:def:64093
Revision Date:2020-12-01Version:1
Title:Security update for apache-commons-httpclient (Important)
Description:

This update for apache-commons-httpclient fixes the following issues:

- http/conn/ssl/SSLConnectionSocketFactory.java ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. [bsc#945190, CVE-2015-5262] - org.apache.http.conn.ssl.AbstractVerifier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows MITM attackers to spoof SSL servers via a 'CN=' string in a field in the distinguished name (DN) of a certificate. [bsc#1178171, CVE-2014-3577]
Family:unixClass:patch
Status:Reference(s):1051510
1065729
1071995
1085030
1104967
1114279
1125433
1136981
1136986
1136992
1137930
1143492
1144333
1144625
1148868
1150660
1152107
1152472
1152624
1153102
1158983
1159058
1159869
1161016
1162002
1162063
1168081
1169194
1169514
1169679
1169748
1169795
1170011
1170592
1170618
1171124
1171424
1171441
1171443
1171444
1171445
1171446
1171447
1171474
1171558
1171673
1171732
1171761
1171868
1171904
1172171
1172257
1172344
1172458
1172484
1172759
1172775
1172781
1172782
1172783
1172999
1173247
1173265
1173280
1173428
1173462
1173514
1173567
1173573
1173605
1174075
1174115
1174200
1174462
1174543
1174582
1178171
1178512
945190
CVE-2014-3577
CVE-2015-5262
CVE-2019-12447
CVE-2019-12448
CVE-2019-12449
CVE-2019-12795
CVE-2019-16746
CVE-2019-17113
CVE-2019-20810
CVE-2019-20908
CVE-2019-5850
CVE-2019-5851
CVE-2019-5852
CVE-2019-5853
CVE-2019-5854
CVE-2019-5855
CVE-2019-5856
CVE-2019-5857
CVE-2019-5858
CVE-2019-5859
CVE-2019-5860
CVE-2019-5861
CVE-2019-5862
CVE-2019-5863
CVE-2019-5864
CVE-2019-5865
CVE-2020-0305
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-11017
CVE-2020-11018
CVE-2020-11019
CVE-2020-11038
CVE-2020-11039
CVE-2020-11040
CVE-2020-11041
CVE-2020-11043
CVE-2020-11085
CVE-2020-11086
CVE-2020-11087
CVE-2020-11088
CVE-2020-11089
CVE-2020-11095
CVE-2020-11096
CVE-2020-11097
CVE-2020-11098
CVE-2020-11099
CVE-2020-11521
CVE-2020-11522
CVE-2020-11523
CVE-2020-11524
CVE-2020-11525
CVE-2020-11526
CVE-2020-12771
CVE-2020-12888
CVE-2020-13396
CVE-2020-13397
CVE-2020-13398
CVE-2020-13974
CVE-2020-14004
CVE-2020-14416
CVE-2020-15393
CVE-2020-15780
CVE-2020-28196
CVE-2020-4030
CVE-2020-4031
CVE-2020-4032
CVE-2020-4033
CVE-2020-6532
CVE-2020-6537
CVE-2020-6538
CVE-2020-6539
CVE-2020-6540
CVE-2020-6541
openSUSE-SU-2019:1697-1
openSUSE-SU-2019:1849-1
openSUSE-SU-2019:2306-1
openSUSE-SU-2020:1090-1
openSUSE-SU-2020:1154-1
openSUSE-SU-2020:1820-1
SUSE-SU-2020:2121-1
SUSE-SU-2020:3379-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • gvfs-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-32bit-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backend-afc-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backend-samba-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backends-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-devel-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-fuse-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-lang-1.34.2.1-lp151.6.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • chromedriver-84.0.4147.105-lp152.2.9 is installed
  • OR chromium-84.0.4147.105-lp152.2.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND apache-commons-httpclient-3.1-6.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • krb5-1.12.5-40.40 is installed
  • OR krb5-32bit-1.12.5-40.40 is installed
  • OR krb5-client-1.12.5-40.40 is installed
  • OR krb5-doc-1.12.5-40.40 is installed
  • OR krb5-plugin-kdb-ldap-1.12.5-40.40 is installed
  • OR krb5-plugin-preauth-otp-1.12.5-40.40 is installed
  • OR krb5-plugin-preauth-pkinit-1.12.5-40.40 is installed
  • OR krb5-server-1.12.5-40.40 is installed
  • BACK