RHSA-2014:1082: Important: thermostat1-httpcomponents-client security update
Thermostat is a monitoring and instrumentation tool for the OpenJDK HotSpotJava Virtual Machine (JVM) with support for monitoring multipleJVM instances.The httpcomponents-client package provides an HTTP agent implementationthat is used by Thermostat to visualize collected data in an HTTP-awareclient application.It was found that the fix for CVE-2012-6153 was incomplete: the code addedto check that the server hostname matches the domain name in a subject'sCommon Name (CN) field in X.509 certificates was flawed.A man-in-the-middle attacker could use this flaw to spoof an SSL serverusing a specially crafted X.509 certificate. (CVE-2014-3577)For additional information on this flaw, refer to the Knowledgebasearticle in the References section.All thermostat1-httpcomponents-client users are advised to upgrade to theseupdated packages, which contain a backported patch to correct this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1082?
The vulnerability RHSA-2014:1082 is classified as important.
How do I fix RHSA-2014:1082?
To fix RHSA-2014:1082, update the thermostat1-httpcomponents-client package to version 4.2.5-3.4.el6.1 or later.
Which software is affected by RHSA-2014:1082?
RHSA-2014:1082 affects the thermostat1-httpcomponents-client and its related packages.
What does RHSA-2014:1082 address?
RHSA-2014:1082 addresses vulnerabilities in the HTTP agent implementation used by Thermostat.
Is RHSA-2014:1082 related to Java Virtual Machine security?
Yes, RHSA-2014:1082 pertains to vulnerabilities impacting the monitoring tool for OpenJDK HotSpot Java Virtual Machine.