{"id":"MGASA-2014-0347","summary":"Updated jakarta-commons-httpclient and httpcomponents-client packages fix security vulnerability","details":"Updated jakarta-commons-httpclient and httpcomponents-client packages fix\nsecurity vulnerability:\n\nThe Jakarta Commons HttpClient and Apache httpcomponents HttpClient\ncomponents may be susceptible to a 'Man in the Middle Attack' due to a flaw\nin the default hostname verification during SSL/TLS when a specially crafted\nserver side certificate is used (CVE-2012-6153).\n","modified":"2026-04-16T01:46:55.869090735Z","published":"2014-08-25T08:44:11Z","upstream":["CVE-2012-6153"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0347.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13932"},{"type":"ADVISORY","url":"http://mail-archives.apache.org/mod_mbox/www-announce/201408.mbox/CVE-2014-3577"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-1082.html"}],"affected":[{"package":{"name":"jakarta-commons-httpclient","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/jakarta-commons-httpclient?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1-10.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0347.json"}},{"package":{"name":"httpcomponents-client","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/httpcomponents-client?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.5-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0347.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}