Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120384
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2013-169)
Zusammenfassung:The remote host is missing an update for the 'jakarta-commons-httpclient' package(s) announced via the ALAS-2013-169 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'jakarta-commons-httpclient' package(s) announced via the ALAS-2013-169 advisory.

Vulnerability Insight:
The Jakarta Commons HttpClient component did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name. (CVE-2012-5783)

Affected Software/OS:
'jakarta-commons-httpclient' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-5783
BugTraq ID: 58073
http://www.securityfocus.com/bid/58073
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
RedHat Security Advisories: RHSA-2013:0270
http://rhn.redhat.com/errata/RHSA-2013-0270.html
RedHat Security Advisories: RHSA-2013:0679
http://rhn.redhat.com/errata/RHSA-2013-0679.html
RedHat Security Advisories: RHSA-2013:0680
http://rhn.redhat.com/errata/RHSA-2013-0680.html
RedHat Security Advisories: RHSA-2013:0681
http://rhn.redhat.com/errata/RHSA-2013-0681.html
RedHat Security Advisories: RHSA-2013:0682
http://rhn.redhat.com/errata/RHSA-2013-0682.html
RedHat Security Advisories: RHSA-2013:1147
http://rhn.redhat.com/errata/RHSA-2013-1147.html
RedHat Security Advisories: RHSA-2013:1853
http://rhn.redhat.com/errata/RHSA-2013-1853.html
RedHat Security Advisories: RHSA-2014:0224
http://rhn.redhat.com/errata/RHSA-2014-0224.html
RedHat Security Advisories: RHSA-2017:0868
https://access.redhat.com/errata/RHSA-2017:0868
SuSE Security Announcement: openSUSE-SU-2013:0354 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00078.html
SuSE Security Announcement: openSUSE-SU-2013:0622 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00040.html
SuSE Security Announcement: openSUSE-SU-2013:0623 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00041.html
SuSE Security Announcement: openSUSE-SU-2013:0638 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00053.html
http://www.ubuntu.com/usn/USN-2769-1
XForce ISS Database: apache-commons-ssl-spoofing(79984)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79984
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.