RHSA-2014:1146: Important: httpcomponents-client security update
HttpClient is an HTTP/1.1 compliant HTTP agent implementation based onhttpcomponents HttpCore.It was discovered that the HttpClient incorrectly extracted host name froman X.509 certificate subject's Common Name (CN) field. A man-in-the-middleattacker could use this flaw to spoof an SSL server using a speciallycrafted X.509 certificate. (CVE-2014-3577)For additional information on this flaw, refer to the Knowledgebasearticle in the References section.All httpcomponents-client users are advised to upgrade to these updatedpackages, which contain a backported patch to correct this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1146?
The severity of RHSA-2014:1146 is classified as Important.
How do I fix RHSA-2014:1146?
To fix RHSA-2014:1146, you should update the httpcomponents-client and related packages to version 4.2.5-5.el7_0.
What software is affected by RHSA-2014:1146?
The affected software includes httpcomponents-client and httpcomponents-client-javadoc in versions prior to 4.2.5-5.el7_0.
What type of attack is associated with RHSA-2014:1146?
RHSA-2014:1146 is associated with a man-in-the-middle attack due to improper hostname extraction from X.509 certificate.
When was RHSA-2014:1146 released?
RHSA-2014:1146 was released in 2014.