|
|
| |
|
| |
jakarta-commons-httpclient: incorrect certificate validation
| Package(s): | jakarta-commons-httpclient |
CVE #(s): | CVE-2012-5783
|
| Created: | February 1, 2013 |
Updated: | April 4, 2013 |
| Description: |
From the Fedora advisory:
This update fixes a security vulnerability that caused jakarta-commons-httpclient not to verify
that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName
field of the X.509 certificate, which allowed man-in-the-middle attackers to spoof SSL servers via
andaarbitrary valid certificate (CVE-2012-5783). |
| Alerts: |
|
( Log in to post comments)
|
|
|