CVE-2012-6153
published 2014-09-04CVE-2012-6153: http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.84%
92.4th percentile
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons-httpclient | >= 0 < 3.1-10.2 | 3.1-10.2 |
| apache | commons-httpclient | >= 0 < 3.1-10.2 | 3.1-10.2 |
| apache | commons-httpclient | >= 0 < 3.1-10.2 | 3.1-10.2 |
| apache | commons-httpclient | >= 0 < 3.1-10.2 | 3.1-10.2 |
| apache | commons-httpclient | 4.0 – 4.2.2 | — |
| debian | commons-httpclient | < commons-httpclient 3.1-10.2 (bookworm) | commons-httpclient 3.1-10.2 (bookworm) |
| jenkins | client_needs_to_be_updated_independently_from_the_plugin | — | — |
| jenkins | jenkins | <= 2.73.1 | — |
| jenkins | jenkins | <= 2.83 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | mailer_plugin | — | — |
| jenkins | maven | <= 2.17 | — |
| jenkins | maven_plugin | — | — |
| jenkins | please_note_that_swarm_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | swarm | <= 3.4 | — |
| jenkins | swarm_plugin | — | — |
| jenkins | updating_just_the_plugin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Certificate Validation in Jenkins
ghsa·2022-05-14·CVSS 4.3
CVE-2017-1000396 [MEDIUM] CWE-295 Improper Certificate Validation in Jenkins
Improper Certificate Validation in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.
GHSA
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
ghsa·2022-05-14·CVSS 4.3
CVE-2017-1000402 [MEDIUM] CWE-20 Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
OSV
Improper Certificate Validation in Jenkins
osv·2022-05-14·CVSS 4.3
CVE-2017-1000396 [MEDIUM] Improper Certificate Validation in Jenkins
Improper Certificate Validation in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.
OSV
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
osv·2022-05-14·CVSS 4.3
CVE-2017-1000402 [MEDIUM] Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
GHSA
MitM on Jenkins Maven Plugin
ghsa·2022-05-14·CVSS 4.3
CVE-2017-1000397 [MEDIUM] CWE-20 MitM on Jenkins Maven Plugin
MitM on Jenkins Maven Plugin
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
OSV
MitM on Jenkins Maven Plugin
osv·2022-05-14·CVSS 4.3
CVE-2017-1000397 [MEDIUM] MitM on Jenkins Maven Plugin
MitM on Jenkins Maven Plugin
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
GHSA
Improper certificate validation in org.apache.httpcomponents:httpclient
ghsa·2018-10-17·CVSS 5.8
CVE-2012-6153 [MEDIUM] CWE-20 Improper certificate validation in org.apache.httpcomponents:httpclient
Improper certificate validation in org.apache.httpcomponents:httpclient
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
OSV
Improper certificate validation in org.apache.httpcomponents:httpclient
osv·2018-10-17·CVSS 5.8
CVE-2012-6153 [MEDIUM] Improper certificate validation in org.apache.httpcomponents:httpclient
Improper certificate validation in org.apache.httpcomponents:httpclient
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
OSV
commons-httpclient vulnerabilities
osv·2015-10-14·CVSS 5.8
CVE-2012-5783 [MEDIUM] commons-httpclient vulnerabilities
commons-httpclient vulnerabilities
It was discovered that Apache Commons HttpClient did not properly verify the
Common Name or subjectAltName fields of X.509 certificates. An attacker could
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-5783)
Florian Weimer discovered the fix for CVE-2012-5783 was incomplete for Apache
Commons HttpClient. An attacker could exploit this to perform a
machine-in-the-middle attack to view sensitive information or alter
encrypted communications. This issue only affected Ubuntu 12.04 LTS.
(CVE-2012-6153)
Subodh Iyengar and Will Shackleton discovered the fix for CVE-2012-5783 was
incomplete for Apache Commons HttpClient. An attacker cou
OSV
CVE-2012-6153: http/conn/ssl/AbstractVerifier
osv·2014-09-04·CVSS 5.8
CVE-2012-6153 [MEDIUM] CVE-2012-6153: http/conn/ssl/AbstractVerifier
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
Red Hat
jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
vendor_redhat·2017-10-11·CVSS 4.3
CVE-2017-1000402 [MEDIUM] CWE-300 jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
Package: jenkins-plugin-swarm (Red Hat OpenShift Enterprise 3) - Not affected
Jenkins
Jenkins Security Advisory 2017-10-11
vendor_jenkins·2017-10-11·CVSS 7.5
CVE-2012-6153 [HIGH] Jenkins Security Advisory 2017-10-11
Title: Jenkins Security Advisory 2017-10-11
Jenkins Security Advisory 2017-10-11
This advisory announces multiple vulnerabilities in Jenkins (weekly and LTS), and these plugins:
Maven Plugin
Swarm Plugin Client
Speaks! Plugin
Description
Arbitrary shell command execution on controller by users with Agent-related permissions
SECURITY-478 / CVE-2017-1000393
Users with permission to create or configure agents in Jenkins could configure a launch method called Launch agent via execution of command on master .
This allowed them to run arbitrary shell commands on the Jenkins controller whenever the agent was supposed to be launched.
Configuration of this launch method now requires the Run Scripts permission typically only granted t
Red Hat
jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
vendor_redhat·2017-10-11·CVSS 4.3
CVE-2017-1000396 [MEDIUM] CWE-300 jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.
Package: jenkins (Red Hat OpenShift Enterprise 3) - Not affected
Ubuntu
Apache Commons HttpClient vulnerabilities
vendor_ubuntu·2015-10-14·CVSS 5.8
CVE-2012-5783 [MEDIUM] Apache Commons HttpClient vulnerabilities
Title: Apache Commons HttpClient vulnerabilities
Summary: Several security issues were fixed in commons-httpclient.
It was discovered that Apache Commons HttpClient did not properly verify the
Common Name or subjectAltName fields of X.509 certificates. An attacker could
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-5783)
Florian Weimer discovered the fix for CVE-2012-5783 was incomplete for Apache
Commons HttpClient. An attacker could exploit this to perform a
machine-in-the-middle attack to view sensitive information or alter
encrypted communications. This issue only affected Ubuntu 12.04 LTS.
(CVE-2012-6153)
Subodh Iyengar and Will Shackleton discovered the f
Red Hat
CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
vendor_redhat·2014-08-18·CVSS 4.3
CVE-2014-3577 [MEDIUM] CWE-297 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.
It was found that the fix for CVE-2012-6153 was incomplete: the code added to check that the server hostname matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could
Red Hat
CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
vendor_redhat·2014-08-14·CVSS 5.8
CVE-2012-6153 [MEDIUM] CWE-297 CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
It was found that the fix for CVE-2012-5783 was incomplete: the code added to check that the server host name matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could use this flaw to spoof
Debian
CVE-2012-6153: commons-httpclient - http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 do...
vendor_debian·2012·CVSS 5.8
CVE-2012-6153 [MEDIUM] CVE-2012-6153: commons-httpclient - http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 do...
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
Scope: local
bookworm: resolved (fixed in 3.1-10.2)
bullseye: resolved (fixed in 3.1-10.2)
forky: resolved (fixed in 3.1-10.2)
sid: resolved (fixed in 3.1-10.2)
trixie: resolved (fixed in 3.1-10.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000402 jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
bugzilla·2017-10-13·CVSS 4.3
CVE-2017-1000402 [MEDIUM] CVE-2017-1000402 jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
CVE-2017-1000402 jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
Swarm Plugin Client bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
External References:
https://jenkins.io/security/advisory/2017-10-11/
Discussion:
swarm plugin not included in latest openshift3/jenkins-2-rhel7 image. Check using this package: https://access.redhat.com/downloads/content/jenkins-2-plugins/3.7.1502412812-1.el7/noarch/fd431d51/package
Bugzilla
CVE-2017-1000396 jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
bugzilla·2017-10-13·CVSS 4.3
CVE-2017-1000396 [MEDIUM] CVE-2017-1000396 jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
CVE-2017-1000396 jenkins: Jenkins core bundled vulnerable version of the commons-httpclient library (SECURITY-555)
Jenkins bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
External References:
https://jenkins.io/security/advisory/2017-10-11/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: openshift-1 [bug 1501973]
---
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1558858]
---
Openshift is now using Jenkins version 2.83.2. Marking both Online and Enterprise as not affected.
Bugzilla
CVE-2014-3577 jakarta-commons-httpclient: SSL hostname verification bypass, incomplete CVE-2012-6153 fix [fedora-all]
bugzilla·2014-08-18·CVSS 4.3
CVE-2014-3577 [MEDIUM] CVE-2014-3577 jakarta-commons-httpclient: SSL hostname verification bypass, incomplete CVE-2012-6153 fix [fedora-all]
CVE-2014-3577 jakarta-commons-httpclient: SSL hostname verification bypass, incomplete CVE-2012-6153 fix [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2012-6153 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
bugzilla·2014-08-14·CVSS 5.8
CVE-2012-6153 [MEDIUM] CVE-2012-6153 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
CVE-2012-6153 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix
It was found that the fix for CVE-2012-5783 was incomplete. The code added to check that the server hostname matches the domain name in the subject's CN field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject.
Discussion:
Acknowledgements:
This issue was discovered by Florian Weimer of Red Hat Product Security.
---
Upstream Commit:
HttpClient/4.2.x Branch
http://svn.apache.org/viewvc?view=revision&revision=1411705
---
Affects:
org.apache.httpcomponents:httpclient This issue has been addressed in following products:
>
> Red Hat Software Collections 1 for Red H
Bugzilla
CVE-2014-3577 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
bugzilla·2014-08-12·CVSS 4.3
CVE-2014-3577 [MEDIUM] CVE-2014-3577 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
CVE-2014-3577 Apache HttpComponents client / Apache CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
It was found that the fix for CVE-2012-6153 was incomplete. The code added to check that the server hostname matches the domain name in the subject's CN field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can spoof a valid certificate using a specially crafted subject.
Discussion:
Statement:
Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/solutions/1165533
This issue affects the versions of HttpComponents Client as shipped with Red Hat JBoss Data Grid 6 and Red Hat JBoss Data Virtualization 6; and ModeShape Client as shipped with Red Hat JBoss Data Virtualization 6. Howeve
Bugzilla
CVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name
bugzilla·2012-11-05·CVSS 5.8
CVE-2012-5783 [MEDIUM] CVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name
CVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5783 to the following vulnerability:
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via andaarbitrary valid certificate.
References:
[1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
[2] https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html
[3] http://www.sigsac.org/ccs/CCS2012/techprogram.shtml
Discussion:
Created jak
arXiv
Impact assessment for vulnerabilities in open-source software libraries
arxiv_fulltext·2015-04-21
Impact assessment for vulnerabilities in open-source software libraries
fancy
Software applications integrate more and more open-source software
(OSS) to benefit from code reuse. As a drawback, each vulnerability
discovered in bundled OSS potentially affects the application. Upon
the disclosure of every new vulnerability, the application vendor has
to decide whether it is exploitable in his particular usage context,
hence, whether users require an urgent application patch containing a
non-vulnerable version of the OSS. Current decision making is mostly
based on high-level vulnerability descriptions and expert knowledge,
thus, effort intense and error prone. This paper proposes a pragmatic
approach to facilitate the impact assessment, describes a
proof-of-concept for Java, and examines one example vulnerability as
case study. The approach is independent from s
http://rhn.redhat.com/errata/RHSA-2014-1098.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1833.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1834.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1835.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1836.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1891.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1892.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0125.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0158.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1888.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1411705http://www.securityfocus.com/bid/69257http://www.ubuntu.com/usn/USN-2769-1https://access.redhat.com/solutions/1165533https://bugzilla.redhat.com/show_bug.cgi?id=1129916https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564http://rhn.redhat.com/errata/RHSA-2014-1098.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1833.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1834.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1835.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1836.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1891.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1892.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0125.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0158.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1888.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1411705http://www.securityfocus.com/bid/69257http://www.ubuntu.com/usn/USN-2769-1https://access.redhat.com/solutions/1165533https://bugzilla.redhat.com/show_bug.cgi?id=1129916https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564
2014-09-04
Published