SUSE-SU-2020:3149-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3149-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2020:3149-1
Related
Published
2020-11-04T10:05:07Z
Modified
2020-11-04T10:05:07Z
Summary
Security update for apache-commons-httpclient
Details

This update for apache-commons-httpclient fixes the following issues:

  • http/conn/ssl/SSLConnectionSocketFactory.java ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. [bsc#945190, CVE-2015-5262]
  • org.apache.http.conn.ssl.AbstractVerifier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows MITM attackers to spoof SSL servers via a 'CN=' string in a field in the distinguished name (DN) of a certificate. [bsc#1178171, CVE-2014-3577]
References

Affected packages

SUSE:HPE Helion OpenStack 8 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=HPE%20Helion%20OpenStack%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:OpenStack Cloud 7 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:OpenStack Cloud 8 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20OpenStack%20Cloud%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:OpenStack Cloud 9 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 8 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP3 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-LTSS / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-BCL / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP3-LTSS / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP3-BCL / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}

SUSE:Enterprise Storage 5 / apache-commons-httpclient

Package

Name
apache-commons-httpclient
Purl
purl:rpm/suse/apache-commons-httpclient&distro=SUSE%20Enterprise%20Storage%205

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-6.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apache-commons-httpclient": "3.1-6.3.1"
        }
    ]
}