RHSA-2014:1166: Important: jakarta-commons-httpclient security update
Jakarta Commons HTTPClient implements the client side of HTTP standards.It was discovered that the HTTPClient incorrectly extracted host name froman X.509 certificate subject's Common Name (CN) field. A man-in-the-middleattacker could use this flaw to spoof an SSL server using a speciallycrafted X.509 certificate. (CVE-2014-3577)For additional information on this flaw, refer to the Knowledgebasearticle in the References section.All jakarta-commons-httpclient users are advised to upgrade to theseupdated packages, which contain a backported patch to correct this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1166?
The severity of RHSA-2014:1166 is classified as important.
How do I fix RHSA-2014:1166?
To fix RHSA-2014:1166, update to the packages jakarta-commons-httpclient 3.1-16.el7_0 or higher.
What does RHSA-2014:1166 affect?
RHSA-2014:1166 affects the Jakarta Commons HTTPClient versions prior to 3.1-16.el7_0.
What kind of vulnerability is addressed in RHSA-2014:1166?
RHSA-2014:1166 addresses a man-in-the-middle vulnerability that allows SSL server spoofing.
Which packages are impacted by RHSA-2014:1166?
The impacted packages include jakarta-commons-httpclient, jakarta-commons-httpclient-demo, and jakarta-commons-httpclient-manual, among others.