Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Fedora 20 FEDORA-2015-6891 Moderate: async-http-client SSL Issues

fedora
Calendar Grey May 8, 2015
Scroller Fedora
Fedora 20 security patch for async-http-client resolves SSL vulnerabilities linked to CVE-2013-7398 and CVE-2013-7397.
Security fix for CVE-2013-7398, CVE-2013-7397

Summary

Async Http Client library purpose is to allow Java applications to

easily execute HTTP requests and asynchronously process the HTTP

responses. The Async HTTP Client library is simple to use.

Update Information:

Security fix for CVE-2013-7398, CVE-2013-7397

Change Log

* Fri Apr 24 2015 Michal Srb - 1.7.22-2 - Resolves: CVE-2013-7397 - Resolves: CVE-2013-7398 * Wed Dec 4 2013 Mikolaj Izdebski - 1.7.22-1 - Update to upstream version 1.7.22 * Fri Oct 18 2013 Michal Srb - 1.7.21-1 - Update to upstream version 1.7.21

References


[ 1 ] Bug #1133773 - CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates https://bugzilla.redhat.com/show_bug.cgi?id=1133773 [ 2 ] Bug #1133769 - CVE-2013-7397 async-http-client: SSL/TLS certificate verification is disabled under certain conditions https://bugzilla.redhat.com/show_bug.cgi?id=1133769

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update async-http-client' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: async-http-client
Product: Fedora 20
Version: 1.7.22
Release: 2.fc20
Summary: Asynchronous Http Client for Java

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.