jakarta-commons-httpclient-3.1-0.9.AXS4

エラータID: AXSA:2014-529:01

Release date: 
Monday, September 15, 2014 - 12:53
Subject: 
jakarta-commons-httpclient-3.1-0.9.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Description:

The Hyper-Text Transfer Protocol (HTTP) is perhaps the most significant protocol used on the Internet today. Web services, network-enabled appliances and the growth of network computing continue to expand the role of the HTTP protocol beyond user-driven web browsers, and increase the number of applications that may require HTTP support.
Although the java.net package provides basic support for accessing resources via HTTP, it doesn't provide the full flexibility or functionality needed by many applications. The Jakarta Commons HTTP Client component seeks to fill this void by providing an efficient, up-to-date, and feature-rich package implementing the client side of the most recent HTTP standards and recommendations.
Designed for extension while providing robust support for the base HTTP protocol, the HTTP Client component may be of interest to anyone building HTTP-aware client applications such as web browsers, web service clients, or systems that leverage or extend the HTTP protocol for distributed communication.

Security issues fixed with this release:

CVE-2014-3577
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

Solution: 

update package.

Additional Info: 

N/A

Download: 

SRPMS
  1. jakarta-commons-httpclient-3.1-0.9.AXS4.src.rpm
    MD5: a0bf59e6ed70bbb5dca80596e115d78b
    SHA-256: 6ba75562d749b9142d9fac4a50b50fd3e4b8ba6e7b0b65584c2a4611183552a7
    Size: 1.81 MB

Asianux Server 4 for x86
  1. jakarta-commons-httpclient-3.1-0.9.AXS4.i686.rpm
    MD5: 262b638fd7a131009331983d12296ada
    SHA-256: 12e6f3a71f5665af2e9847be3d1fc36a7175c25edbd283f5f04000caaeeb2d1c
    Size: 468.68 kB

Asianux Server 4 for x86_64
  1. jakarta-commons-httpclient-3.1-0.9.AXS4.x86_64.rpm
    MD5: d26b43fda780a82120b3855b8444f82a
    SHA-256: 40eafed41f1fcce56d2c20cec92d333d2809b18ac4a84491b25c8bf0358d629d
    Size: 529.99 kB