CVE-2015-5262
published 2015-10-27CVE-2015-5262: http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an…
PriorityP430medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
19.31%
97.0th percentile
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpclient | 4.3 – 4.3.5 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | commons-httpclient | < commons-httpclient 3.1-12 (bookworm) | commons-httpclient 3.1-12 (bookworm) |
| debian | httpcomponents-client | < commons-httpclient 3.1-12 (bookworm) | commons-httpclient 3.1-12 (bookworm) |
| debian | python-pykmip | < python-pykmip 0.7.0-3 (bookworm) | python-pykmip 0.7.0-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jenkins | azure_slave_plugin | — | — |
| jenkins | azure_vm_agents_plugin | — | — |
| jenkins | coverity_plugin | — | — |
| jenkins | cppncss_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | envinject_plugin | — | — |
| jenkins | environment_injector_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | google_play_android_publisher_plugin | — | — |
| jenkins | ids_in_google_play_android_publisher_plugin | — | — |
| jenkins | improper_access_control_in_gerrit_trigger_plugin | — | — |
| jenkins | job_and_node_ownership_plugin | — | — |
| jenkins | mercurial_plugin | — | — |
| jenkins | testlink_plugin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa4.3MEDIUM
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-pykmip: DoS due to undefined default timeout for all server sockets
vendor_redhat·2018-04-24·CVSS 4.3
CVE-2018-1000872 [MEDIUM] CWE-400 python-pykmip: DoS due to undefined default timeout for all server sockets
python-pykmip: DoS due to undefined default timeout for all server sockets
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clients opening all of the available sockets. This attack appear to be exploitable via A client or clients open sockets with the server and then never close them. This vulnerability appears to have been fixed in 0.8.0.
Package: python-pykmip (Red Hat OpenStack Platform 13 (Queens)) - Fix deferred
Package: python-pykmip (Red Hat OpenStack Platform 14 (Rocky)) - Affected
Jenkins
Jenkins Security Advisory 2018-02-26
vendor_jenkins·2018-02-26
CVE-2015-5262 [MEDIUM] Jenkins Security Advisory 2018-02-26
Title: Jenkins Security Advisory 2018-02-26
Jenkins Security Advisory 2018-02-26
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Azure Slave
Plugin
Coverity
Plugin
CppNCSS
Plugin
Environment Injector
Plugin
Gerrit Trigger
Plugin
Git
Plugin
Google Play Android Publisher
Plugin
Job and Node o
Debian
CVE-2018-1000872: python-pykmip - OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource M...
vendor_debian·2018·CVSS 4.3
CVE-2018-1000872 [MEDIUM] CVE-2018-1000872: python-pykmip - OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource M...
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clients opening all of the available sockets. This attack appear to be exploitable via A client or clients open sockets with the server and then never close them. This vulnerability appears to have been fixed in 0.8.0.
Scope: local
bookworm: resolved (fixed in 0.7.0-3)
bullseye: resolved (fixed in 0.7.0-3)
forky: resolved (fixed in 0.7.0-3)
sid: resolved (fixed in 0.7.0-3)
trixie: resolved (fixed in 0.7.0-3)
Ubuntu
Apache Commons HttpClient vulnerabilities
vendor_ubuntu·2015-10-14·CVSS 5.8
CVE-2012-5783 [MEDIUM] Apache Commons HttpClient vulnerabilities
Title: Apache Commons HttpClient vulnerabilities
Summary: Several security issues were fixed in commons-httpclient.
It was discovered that Apache Commons HttpClient did not properly verify the
Common Name or subjectAltName fields of X.509 certificates. An attacker could
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-5783)
Florian Weimer discovered the fix for CVE-2012-5783 was incomplete for Apache
Commons HttpClient. An attacker could exploit this to perform a
machine-in-the-middle attack to view sensitive information or alter
encrypted communications. This issue only affected Ubuntu 12.04 LTS.
(CVE-2012-6153)
Subodh Iyengar and Will Shackleton discovered the f
Red Hat
httpcomponents-core: missing HTTPS connection timeout
vendor_redhat·2015-09-03·CVSS 4.3
CVE-2015-5262 [MEDIUM] CWE-770 httpcomponents-core: missing HTTPS connection timeout
httpcomponents-core: missing HTTPS connection timeout
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Package: jakarta-commons-httpclient (Red Hat Enterprise Linux 5) - Will not fix
Package: jakarta-commons-httpclient (Red Hat Enterprise Linux 6) - Affected
Package: httpcomponents-core (Red Hat Enterprise Linux 7) - Not affected
Package: jakarta-commons-httpclient (Red Hat Enterprise Linux 7) - Affected
Package: ovirt-engine-sdk-java (Red Hat Virtualization 4) - Affected
Debian
CVE-2015-5262: commons-httpclient - http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClien...
vendor_debian·2015·CVSS 4.3
CVE-2015-5262 [MEDIUM] CVE-2015-5262: commons-httpclient - http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClien...
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.1-12)
bullseye: resolved (fixed in 3.1-12)
forky: resolved (fixed in 3.1-12)
sid: resolved (fixed in 3.1-12)
trixie: resolved (fixed in 3.1-12)
GHSA
PyKMIP Denial of service vulnerability
ghsa·2018-12-21·CVSS 4.3
CVE-2018-1000872 [MEDIUM] CWE-400 PyKMIP Denial of service vulnerability
PyKMIP Denial of service vulnerability
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clients opening all of the available sockets. This attack appear to be exploitable via A client or clients open sockets with the server and then never close them. This vulnerability appears to have been fixed in 0.8.0.
OSV
PyKMIP Denial of service vulnerability
osv·2018-12-21·CVSS 4.3
CVE-2018-1000872 [MEDIUM] PyKMIP Denial of service vulnerability
PyKMIP Denial of service vulnerability
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clients opening all of the available sockets. This attack appear to be exploitable via A client or clients open sockets with the server and then never close them. This vulnerability appears to have been fixed in 0.8.0.
OSV
CVE-2018-1000872: OpenKMIP PyKMIP version All versions before 0
osv·2018-12-20·CVSS 4.3
CVE-2018-1000872 [MEDIUM] CVE-2018-1000872: OpenKMIP PyKMIP version All versions before 0
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clients opening all of the available sockets. This attack appear to be exploitable via A client or clients open sockets with the server and then never close them. This vulnerability appears to have been fixed in 0.8.0.
OSV
Denial of service vulnerability in org.apache.httpcomponents:httpclient
osv·2018-10-17
CVE-2015-5262 [MEDIUM] Denial of service vulnerability in org.apache.httpcomponents:httpclient
Denial of service vulnerability in org.apache.httpcomponents:httpclient
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
GHSA
Denial of service vulnerability in org.apache.httpcomponents:httpclient
ghsa·2018-10-17
CVE-2015-5262 [MEDIUM] Denial of service vulnerability in org.apache.httpcomponents:httpclient
Denial of service vulnerability in org.apache.httpcomponents:httpclient
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
OSV
CVE-2015-5262: http/conn/ssl/SSLConnectionSocketFactory
osv·2015-10-27·CVSS 4.3
CVE-2015-5262 [MEDIUM] CVE-2015-5262: http/conn/ssl/SSLConnectionSocketFactory
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
OSV
commons-httpclient vulnerabilities
osv·2015-10-14·CVSS 5.8
CVE-2012-5783 [MEDIUM] commons-httpclient vulnerabilities
commons-httpclient vulnerabilities
It was discovered that Apache Commons HttpClient did not properly verify the
Common Name or subjectAltName fields of X.509 certificates. An attacker could
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-5783)
Florian Weimer discovered the fix for CVE-2012-5783 was incomplete for Apache
Commons HttpClient. An attacker could exploit this to perform a
machine-in-the-middle attack to view sensitive information or alter
encrypted communications. This issue only affected Ubuntu 12.04 LTS.
(CVE-2012-6153)
Subodh Iyengar and Will Shackleton discovered the fix for CVE-2012-5783 was
incomplete for Apache Commons HttpClient. An attacker cou
No detection rules found.
No public exploits indexed.
Bugzilla
Fix for CVE-2015-5262 not backported to 4.2.x
bugzilla·2019-03-25·CVSS 4.3
CVE-2015-5262 [MEDIUM] Fix for CVE-2015-5262 not backported to 4.2.x
Fix for CVE-2015-5262 not backported to 4.2.x
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days
Bugzilla
CVE-2018-1000872 python-pykmip: DoS due to undefined default timeout for all server sockets
bugzilla·2019-01-11·CVSS 4.3
CVE-2018-1000872 [MEDIUM] CVE-2018-1000872 python-pykmip: DoS due to undefined default timeout for all server sockets
CVE-2018-1000872 python-pykmip: DoS due to undefined default timeout for all server sockets
A flaw was found in OpenKMIP PyKMIP versions before 0.8.0. A Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS due to undefined default timeout for all server sockets
References:
https://github.com/OpenKMIP/PyKMIP/issues/430
Upstream Patch:
https://github.com/OpenKMIP/PyKMIP/commit/3a7b880bdf70d295ed8af3a5880bab65fa6b3932
Discussion:
Created python-pykmip tracking bugs for this issue:
Affects: fedora-all [bug 1665593]
---
This flaw affects the python-pykmip's server, which RH would probably not support in a RHOSP production deployment although it might be used for testing. Lowering impact for this reason. https://pykmip.readthe
Bugzilla
CVE-2015-5262 jakarta-commons-httpclient: jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout [fedora-all]
bugzilla·2015-09-11·CVSS 4.3
CVE-2015-5262 [MEDIUM] CVE-2015-5262 jakarta-commons-httpclient: jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout [fedora-all]
CVE-2015-5262 jakarta-commons-httpclient: jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2015-5262 jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout
bugzilla·2015-09-09·CVSS 4.3
CVE-2015-5262 [MEDIUM] CVE-2015-5262 jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout
CVE-2015-5262 jakarta-commons-httpclient, httpcomponents-core: missing HTTPS connection timeout
It was discovered that Apache HttpClient did not apply a configured
connection or read timeout during the initial handshake of an HTTPS
connection. As a result, HTTPS connection could get stuck, causing
a denial of service if multiple such connections accumulate.
Discussion:
Upstream patch:
http://svn.apache.org/viewvc/httpcomponents/httpclient/branches/4.3.x/httpclient/src/main/java/org/apache/http/conn/ssl/SSLConnectionSocketFactory.java?r1=1560975&r2=1626784
Originally reported in bug 1259892
---
I could not reproduce this issue with HttpClient 4.2.x, mostly due to lack of relevant APIs. According to the upstream report, it was fixed in version 4.3.6 of the 4.3.x branch.
---
External
Bugzilla
CVE-2015-5262 jakarta-commons-httpclient: https calls ignore http.socket.timeout during SSL Handshake
bugzilla·2015-09-03·CVSS 4.3
CVE-2015-5262 [MEDIUM] CVE-2015-5262 jakarta-commons-httpclient: https calls ignore http.socket.timeout during SSL Handshake
CVE-2015-5262 jakarta-commons-httpclient: https calls ignore http.socket.timeout during SSL Handshake
Description of problem:
We have a multi-threaded Java application which makes dozens of connections to the Amazon SQS web service to read messages every 15 minutes. Occasionally -- about once a day or so now -- one of the threads will hang, preventing the application from terminating and blocking subsequent runs until we find out about it and kill the process.
After taking some Java stack dumps while hung and some research we found that the Apache httpclient library had a bug where the socket timeout was ignored during the SSL handshake:
https://issues.apache.org/jira/browse/HTTPCLIENT-1478
This was reportedly fixed in version 4.3.6 of httpcomponents-client, but RHEL6 only has commons-
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/167962.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/167999.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00033.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1626784http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securitytracker.com/id/1033743http://www.ubuntu.com/usn/USN-2769-1https://bugzilla.redhat.com/show_bug.cgi?id=1261538https://issues.apache.org/jira/browse/HTTPCLIENT-1478https://jenkins.io/security/advisory/2018-02-26/https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/167962.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/167999.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00033.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1626784http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securitytracker.com/id/1033743http://www.ubuntu.com/usn/USN-2769-1https://bugzilla.redhat.com/show_bug.cgi?id=1261538https://issues.apache.org/jira/browse/HTTPCLIENT-1478https://jenkins.io/security/advisory/2018-02-26/https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
2015-10-27
Published