MGASA-2015-0212
Dashboard / Vulnerabilities / MGASA-2015-0212
Summary: Updated async-http-client packages fix security vulnerabilities
Details: Updated async-http-client packages fix security vulnerabilities: It was found that async-http-client would disable SSL/TLS certificate verification under certain conditions, for example if HTTPS communication also uses client certificates. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can spoof a valid certificate (CVE-2013-7397). It was found that async-http-client did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name (CVE-2013-7398).
References: https://advisories.mageia.org/MGASA-2015-0212.html, https://bugs.mageia.org/show_bug.cgi?id=15887, https://lists.fedoraproject.org/pipermail/package-announce/2015-May/157337.html
Affected packages
Package
Name: async-http-client
Purl: pkg:rpm/mageia/async-http-client?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
