Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 22 FEDORA-2015-10235 Critical: OpenSAML Java Hostname Verification

fedora
Calendar Grey August 7, 2015
Dist Fedora Esm H88
This modification resolves the OpenSAML Java concern regarding the absence of hostname verification for HTTPS connections stemming from HTTP resources.
* OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification

Summary

The OpenWS library provides a growing set of tools to work with web services at

a low level. These tools include classes for creating and reading SOAP

messages, transport-independent clients for connecting to web services,

and various transports for use with those clients.

Update Information:

* OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification

Change Log

* Tue Jun 16 2015 Marek Goldmann - 1.5.5-2 - Use mvn BR for tomcat API * Fri May 8 2015 Marek Goldmann - 1.5.5-1 - Upstream release 1.5.5

References


[ 1 ] Bug #1131823 - CVE-2014-3603 OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification https://bugzilla.redhat.com/show_bug.cgi?id=1131823

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update opensaml-java-openws' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: opensaml-java-openws
Product: Fedora 22
Version: 1.5.5
Release: 2.fc22
URL: /
Summary: Java OpenWS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here