CVE-2012-5783

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2012-5783 at MITRE

Description

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

NVD CVSS v2 Base Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)

SUSE information

SUSE Bugzilla entries: 803332, 803333

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Builds
SAT Patch Nr: 7574
SUSE Manager 1.2 for SLE 11 SP1
  • jakarta-commons-httpclient3 >= 3.0.1-253.36.1
Builds
SAT Patch Nr: 7572
openSUSE 12.3
  • jakarta-commons-httpclient >= 3.1-4.5.1
  • jakarta-commons-httpclient-demo >= 3.1-4.5.1
  • jakarta-commons-httpclient-javadoc >= 3.1-4.5.1
  • jakarta-commons-httpclient-manual >= 3.1-4.5.1
Patchnames:
openSUSE-2013-304
openSUSE Evergreen 11.4
  • jakarta-commons-httpclient3 >= 3.0.1-313.1
  • jakarta-commons-httpclient3-demo >= 3.0.1-313.1
  • jakarta-commons-httpclient3-javadoc >= 3.0.1-313.1
  • jakarta-commons-httpclient3-manual >= 3.0.1-313.1
Patchnames:
2013-60