CVE-2012-5783
Publication date 4 November 2012
Last updated 24 July 2024
Ubuntu priority
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
commons-httpclient | ||
14.04 LTS trusty |
Not affected
|
|
httpcomponents-client | ||
14.04 LTS trusty |
Not affected
|
|
Notes
seth-arnold
Apache Commons HttpClient has been replaced by HttpComponents
mdeslaur
debian released 3.1-10.1 with a possible regression fix was incomplete, see CVE-2012-6153 and CVE-2014-3577
Patch details
Package | Patch details |
---|---|
commons-httpclient | |
httpcomponents-client |
References
Related Ubuntu Security Notices (USN)
- USN-2769-1
- Apache Commons HttpClient vulnerabilities
- 14 October 2015