LWN.net Logo

jakarta-commons-httpclient: incorrect certificate validation

Package(s):jakarta-commons-httpclient CVE #(s):CVE-2012-5783
Created:February 1, 2013 Updated:April 4, 2013
Description:

From the Fedora advisory:

This update fixes a security vulnerability that caused jakarta-commons-httpclient not to verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allowed man-in-the-middle attackers to spoof SSL servers via andaarbitrary valid certificate (CVE-2012-5783).

Alerts:
Fedora FEDORA-2013-1289 2013-02-01
Fedora FEDORA-2013-1189 2013-02-01
Fedora FEDORA-2013-1203 2013-02-01
Red Hat RHSA-2013:0270-01 2013-02-19
CentOS CESA-2013:0270 2013-02-20
Scientific Linux SL-jaka-20130220 2013-02-20
Oracle ELSA-2013-0270 2013-02-20
Oracle ELSA-2013-0270 2013-02-21
openSUSE openSUSE-SU-2013:0354-1 2013-02-27
openSUSE openSUSE-SU-2013:0622-1 2013-04-04
openSUSE openSUSE-SU-2013:0623-1 2013-04-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds