CVE-2014-3577

Description

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a CN= string in a field in the distinguished name (DN) of a certificate, as demonstrated by the foo,CN=www.apache.org string in the O field.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
2.398

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM WebSphere 9.0.5.8Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.20Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.9Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.12Windows
Vulnerabilities CVE-2014-3577 are fixed in Apache-httpclient 4.3.5Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.3.0.2.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.4.0.0.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.4.0.1.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.5.0.1.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.5.0.2.0Windows
Vulnerabilities CVE-2014-3577 are affected in Oracle Financial Services Revenue Management and Billing 2.5.0.3.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.10Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6Windows
A Java(TM) library for creating HTTP clients (USN-2769-1) libcommons-httpclient-java_3.1-10ubuntu0.1_all.debLinux
A Java(TM) library for creating HTTP clients (USN-2769-1) libcommons-httpclient-java_3.1-10.2ubuntu0.14.04.1_all.debLinux
A Java(TM) library for creating HTTP clients (USN-2769-1) libcommons-httpclient-java_3.1-10.2ubuntu0.15.04.1_all.debLinux
Httpcomponents-client security update (CESA-2014:1146) httpcomponents-client-4.2.5-5.el7_0.noarch.rpmLinux
Httpcomponents-client security update (CESA-2014:1146) httpcomponents-client-javadoc-4.2.5-5.el7_0.noarch.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-demo-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-demo-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-manual-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-manual-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient security update (CESA-2014:1166) jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.x86_64.rpmLinux
(RHSA-2014:1146) Important: httpcomponents-client security update httpcomponents-client-4.2.5-5.el7_0.noarch.rpmLinux
(RHSA-2014:1146) Important: httpcomponents-client security update httpcomponents-client-javadoc-4.2.5-5.el7_0.noarch.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-3.0-7jpp.4.el5_10.i386.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-3.0-7jpp.4.el5_10.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-3.1-0.9.el6_5.i686.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-3.1-0.9.el6_5.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-3.1-16.el7_0.noarch.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-demo-3.0-7jpp.4.el5_10.i386.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-demo-3.0-7jpp.4.el5_10.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-demo-3.1-0.9.el6_5.i686.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-demo-3.1-0.9.el6_5.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-demo-3.1-16.el7_0.noarch.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-javadoc-3.0-7jpp.4.el5_10.i386.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-javadoc-3.0-7jpp.4.el5_10.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.i686.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-javadoc-3.1-16.el7_0.noarch.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-manual-3.0-7jpp.4.el5_10.i386.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-manual-3.0-7jpp.4.el5_10.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-manual-3.1-0.9.el6_5.i686.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-manual-3.1-0.9.el6_5.x86_64.rpmLinux
(RHSA-2014:1166) Important: jakarta-commons-httpclient security update jakarta-commons-httpclient-manual-3.1-16.el7_0.noarch.rpmLinux
(RHSA-2016:1237) Important: ImageMagick security update ImageMagick-devel-6.7.2.7-5.el6_8.x86_64.rpmLinux
(RHSA-2016:1237) Important: ImageMagick security update ImageMagick-doc-6.7.2.7-5.el6_8.x86_64.rpmLinux
(RHSA-2016:1237) Important: ImageMagick security update ImageMagick-perl-6.7.2.7-5.el6_8.x86_64.rpmLinux
SUSE-SU-2020:3149-1(SUSE Linux Enterprise Server 12-SP5 ) apache-commons-httpclient-3.1-6.3.1.noarch.rpmLinux
Jakarta-commons-httpclient update (ELSA-2014-1166) jakarta-commons-httpclient-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient-demo update (ELSA-2014-1166) jakarta-commons-httpclient-demo-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient-javadoc update (ELSA-2014-1166) jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient-manual update (ELSA-2014-1166) jakarta-commons-httpclient-manual-3.1-0.9.el6_5.x86_64.rpmLinux
Jakarta-commons-httpclient update (ELSA-2014-1166) jakarta-commons-httpclient-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient-demo update (ELSA-2014-1166) jakarta-commons-httpclient-demo-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient-javadoc update (ELSA-2014-1166) jakarta-commons-httpclient-javadoc-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient-manual update (ELSA-2014-1166) jakarta-commons-httpclient-manual-3.1-0.9.el6_5.i686.rpmLinux
Jakarta-commons-httpclient update (ELSA-2014-1166) jakarta-commons-httpclient-3.1-16.el7_0.noarch.rpmLinux
Jakarta-commons-httpclient-demo update (ELSA-2014-1166) jakarta-commons-httpclient-demo-3.1-16.el7_0.noarch.rpmLinux
Jakarta-commons-httpclient-javadoc update (ELSA-2014-1166) jakarta-commons-httpclient-javadoc-3.1-16.el7_0.noarch.rpmLinux
Jakarta-commons-httpclient-manual update (ELSA-2014-1166) jakarta-commons-httpclient-manual-3.1-16.el7_0.noarch.rpmLinux
Vulnerabilities CVE-2014-3577 are fixed in Apache-httpclient for Linux 4.3.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234