Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE 2024:4036-1 moderate: Security patches for httpcomponents packages

suse
Calendar Grey November 18, 2024
Dist Suse Esm H88
Critical advisory on security flaws in httpcomponents-client and httpcomponents-core affecting SUSE platforms
* bsc#1177488 Cross-References: * CVE-2020-13956

Summary

## This update for httpcomponents-client, httpcomponents-core fixes the following issues: httpcomponents-client: \- Update to version 4.5.14 * HTTPCLIENT-2206: Corrected resource de-allocation by fluent response objects. * HTTPCLIENT-2174: URIBuilder to return a new empty list instead of unmodifiable Collections#emptyList. * Don't retry requests in case of NoRouteToHostException. * HTTPCLIENT-2144: RequestBuilder fails to correctly copy charset of requests with form url-encoded body. * PR #269: 4.5.x use array fill and more. \+ Use Arrays.fill(). \+ Remove redundant modifiers. \+ Use Collections.addAll() and Collection.addAll() APIs instead of loops. \+ Remove redundant returns. \+ No need to explicitly declare an array when calling a vararg method. \+ Remote extra semicolons (;). \+ Use a

References

* bsc#1177488

Cross-

* CVE-2020-13956

CVSS scores:

* CVE-2020-13956 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

* CVE-2020-13956 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products:

* Development Tools Module 15-SP5

* Development Tools Module 15-SP6

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise Real Time 15 SP5

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Manager Server 4.3

* SUSE Manager Server 4.3 Module 4.3

Announcement ID: SUSE-SU-2024:4036-1
Release Date: 2024-11-18T15:24:16Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here