Description
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-322-1 | commons-httpclient security update |
EUVD |
EUVD-2018-0592 | http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. |
Github GHSA |
GHSA-fmj5-wv96-r2ch | Denial of service vulnerability in org.apache.httpcomponents:httpclient |
Ubuntu USN |
USN-2769-1 | Apache Commons HttpClient vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:09.189Z
Reserved: 2015-07-01T00:00:00.000Z
Link: CVE-2015-5262
No data.
Status : Modified
Published: 2015-10-27T16:59:07.557
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-5262
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN