CVE-2012-6153
Publication date 4 September 2014
Last updated 24 July 2024
Ubuntu priority
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
Status
Package | Ubuntu Release | Status |
---|---|---|
commons-httpclient | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
httpcomponents-client | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Notes
Patch details
Package | Patch details |
---|---|
commons-httpclient | |
httpcomponents-client |
References
Related Ubuntu Security Notices (USN)
- USN-2769-1
- Apache Commons HttpClient vulnerabilities
- 14 October 2015