Release date:
Updated on:
Affected Systems:
Apache Group Commons HttpClient 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58073
CVE (CAN) ID: CVE-2012-5783
HttpClient is a sub-project under Apache Jakarta Common. It can be used to provide an efficient, up-to-date, and function-rich client programming toolkit that supports HTTP protocol, it also supports the latest HTTP Version and recommendations.
The Apache Commons HttpClient used by Amazon Flexible Payments Service (FPS) merchant Java SDK product does not correctly verify whether the host name matches the domain name in CN or the domain name in the subjectAltName field of X.509 Certificate, attackers can use arbitrary legitimate certificates to conduct man-in-the-middle attacks and cheat SSL servers.
<* Source: Martin Georgiev
Subodh Iyengar
Suman Jana
Rishita Anubhai
Dan Boneh
Vitaly Shmatikov
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://hc.apache.org/httpclient-3.x/