Oval Definition:oval:org.opensuse.security:def:86000
Revision Date:2020-11-04Version:1
Title:Security update for apache-commons-httpclient (Important)
Description:

This update for apache-commons-httpclient fixes the following issues:

- http/conn/ssl/SSLConnectionSocketFactory.java ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. [bsc#945190, CVE-2015-5262] - org.apache.http.conn.ssl.AbstractVerifier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows MITM attackers to spoof SSL servers via a 'CN=' string in a field in the distinguished name (DN) of a certificate. [bsc#1178171, CVE-2014-3577]
Family:unixClass:patch
Status:Reference(s):1178171
945190
CVE-2014-3577
CVE-2015-5262
SUSE-SU-2020:3149-1
Platform(s):SUSE Linux Enterprise Server 12 SP3-BCL
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND apache-commons-httpclient-3.1-6.3.1 is installed
  • BACK