CVE-2012-5783
CVE-2012-5783
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-updates/2013-02/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00041.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0270.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0679.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0680.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0681.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0682.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1147.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1853.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0224.html