CVE-2012-5783

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2012-5783 at MITRE

Description

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 5.76
Vector AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 803332 [RESOLVED / FIXED], 803333 [RESOLVED / INVALID]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP2
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Patchnames:
slessp2-jakarta-commons-httpclient3
SUSE Linux Enterprise Server for VMWare 11 SP2
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Patchnames:
slessp2-jakarta-commons-httpclient3
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Builds
SAT Patch Nr: 7574
SUSE Manager 1.2 for SLE 11 SP1
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Builds
SAT Patch Nr: 7572
openSUSE 12.3
  • jakarta-commons-httpclient >= 3.1-4.5.1
  • jakarta-commons-httpclient-demo >= 3.1-4.5.1
  • jakarta-commons-httpclient-javadoc >= 3.1-4.5.1
  • jakarta-commons-httpclient-manual >= 3.1-4.5.1
Patchnames:
openSUSE-2013-304
openSUSE Evergreen 11.4
  • jakarta-commons-httpclient3 >= 3.0.1-313.1
  • jakarta-commons-httpclient3-demo >= 3.0.1-313.1
  • jakarta-commons-httpclient3-javadoc >= 3.0.1-313.1
  • jakarta-commons-httpclient3-manual >= 3.0.1-313.1
Patchnames:
2013-60