CVE-2015-5262
commons-httpclient - security update
EPSS 19.3%
描述
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
如何修補 CVE-2015-5262
要修補 CVE-2015-5262,請將受影響套件升級到下列已修補版本。
- Debian/commons-httpclient—升級至 3.1-12 或更新版本
- Debian/commons-httpclient—升級至 3.1-9+deb6u2 或更新版本
- Debian/httpcomponents-client—升級至 4.3.6-1 或更新版本
- —升級至 4.3.6 或更新版本
CVE-2015-5262 正在被利用嗎?
中等 — EPSS 為 19.3%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 3.1-12
- from 0, < 3.1-9+deb6u2
- from 0, < 4.3.6-1
- from 0, < 4.3.6