jakarta-commons-httpclient-3.1-0.7.AXS4

エラータID: AXSA:2013-313:01

Release date: 
Wednesday, April 3, 2013 - 12:19
Subject: 
jakarta-commons-httpclient-3.1-0.7.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

The Hyper-Text Transfer Protocol (HTTP) is perhaps the most significant protocol used on the Internet today. Web services, network-enabled appliances and the growth of network computing continue to expand the role of the HTTP protocol beyond user-driven web browsers, and increase the number of applications that may require HTTP support. Although the java.net package provides basic support for accessing resources via HTTP, it doesn't provide the full flexibility or functionality needed by many applications. The Jakarta Commons HTTP Client component seeks to fill this void by providing an efficient, up-to-date, and feature-rich package implementing the client side of the most recent HTTP standards and recommendations. Designed for extension while providing robust support for the base HTTP protocol, the HTTP Client component may be of interest to anyone building HTTP-aware client applications such as web browsers, web service clients, or systems that leverage or extend the HTTP protocol for distributed communication.

Security issues fixed with this release:

• CVE-2012-5783
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. jakarta-commons-httpclient-3.1-0.7.AXS4.src.rpm
    MD5: ea12b7caef20eb3cd3236c22d46787a3
    SHA-256: 6cfee05c8ccc26379dd6204b4c31a4fbc93bbc183b87bd047dc51954ff2feae3
    Size: 1.80 MB

Asianux Server 4 for x86
  1. jakarta-commons-httpclient-3.1-0.7.AXS4.i686.rpm
    MD5: f51c3b7357bbf4eac9be7eb6b5305b0f
    SHA-256: ce4874ec076a25822fa8e0172933cb6a2b5d1ad47547d226112cd9472df2cb0b
    Size: 463.84 kB

Asianux Server 4 for x86_64
  1. jakarta-commons-httpclient-3.1-0.7.AXS4.x86_64.rpm
    MD5: e96129ec6ae136fed1c061f924be6a75
    SHA-256: c21eee772bdbd2f3683d4490d5c5ddb1a7e53200fc14ea27385fa64faddd44e4
    Size: 524.73 kB