CVE-2015-5262
commons-httpclient - security update
EPSS 19.3%
Description
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
How to fix CVE-2015-5262
To remediate CVE-2015-5262, upgrade the affected package to a fixed version below.
- Debian/commons-httpclient—upgrade to 3.1-12 or later
- Debian/commons-httpclient—upgrade to 3.1-9+deb6u2 or later
- —upgrade to 4.3.6-1 or later
- —upgrade to 4.3.6 or later
Is CVE-2015-5262 being exploited?
Moderate — EPSS is 19.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (4)
- from 0, < 3.1-12
- from 0, < 3.1-9+deb6u2
- from 0, < 4.3.6-1
- from 0, < 4.3.6