LWN.net Logo

Fedora alert FEDORA-2013-1222 (axis)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 18 Update: axis-1.4-19.fc18
Date:  Fri, 01 Feb 2013 16:58:10 +0000
Message-ID:  <20130201165810.5714E210D8@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-1222 2013-01-23 00:31:56 -------------------------------------------------------------------------------- Name : axis Product : Fedora 18 Version : 1.4 Release : 19.fc18 URL : http://ws.apache.org/axis/ Summary : SOAP implementation in Java Description : Apache AXIS is an implementation of the SOAP ("Simple Object Access Protocol") submission to W3C. From the draft W3C specification: SOAP is a lightweight protocol for exchange of information in a decentralized, distributed environment. It is an XML based protocol that consists of three parts: an envelope that defines a framework for describing what is in a message and how to process it, a set of encoding rules for expressing instances of application-defined datatypes, and a convention for representing remote procedure calls and responses. This project is a follow-on to the Apache SOAP project. -------------------------------------------------------------------------------- Update Information: This update fixes a security vulnerability that caused axis not to verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allowed man-in-the-middle attackers to spoof SSL servers via andaarbitrary valid certificate (CVE-2012-5784). -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 21 2013 Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.4-19 - Add missing connection hostname check against X.509 certificate name - Resolves: CVE-2012-5784 -------------------------------------------------------------------------------- References: [ 1 ] Bug #873252 - CVE-2012-5784 axis: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate https://bugzilla.redhat.com/show_bug.cgi?id=873252 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update axis' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds