imPC@ndo IT

Tracker / CVE-2015-5262

CVE-2015-5262

Medium 4.3

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

Affected products and versions

apache httpclient · 4.3 → 4.3.5
canonical ubuntu_linux
fedoraproject fedora

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References