oval:org.mitre.oval:def:26509

Definition Id: oval:org.mitre.oval:def:26509
 
Oval ID: oval:org.mitre.oval:def:26509
Title: ELSA-2014-1146 -- httpcomponents-client security update (Important)
Description: HttpClient is an HTTP/1.1 compliant HTTP agent implementation based on httpcomponents HttpCore. It was discovered that the HttpClient incorrectly extracted host name from an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate. (CVE-2014-3577) For additional information on this flaw, refer to the Knowledgebase article in the References section. All httpcomponents-client users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue.
Family: unix Class: patch
Reference(s): ELSA-2014-1146
CVE-2014-3577
CVE-2012-6153
Version: 3
Platform(s): Oracle Linux 7
Product(s): httpcomponents-client
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25183
 
Oval ID: oval:org.mitre.oval:def:25183
Title: Oracle Linux 7.x
Description: The operating system installed on the system is Oracle Linux 7.x
Family: unix Class: inventory
Reference(s): cpe:/o:oracle:linux:7
Version: 3
Platform(s): Oracle Linux 7
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:26509