CVE Vulnerabilities

CVE-2015-5262

Published: Oct 27, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical15.04 (including)15.04 (including)
FedoraFedoraproject21 (including)21 (including)
FedoraFedoraproject22 (including)22 (including)
FedoraFedoraproject23 (including)23 (including)
Commons-httpclientUbuntuartful*
Commons-httpclientUbuntubionic*
Commons-httpclientUbuntucosmic*
Commons-httpclientUbuntudevel*
Commons-httpclientUbuntudisco*
Commons-httpclientUbuntueoan*
Commons-httpclientUbuntuesm-apps/bionic*
Commons-httpclientUbuntuesm-apps/focal*
Commons-httpclientUbuntuesm-apps/jammy*
Commons-httpclientUbuntuesm-apps/xenial*
Commons-httpclientUbuntuesm-infra-legacy/trusty*
Commons-httpclientUbuntufocal*
Commons-httpclientUbuntugroovy*
Commons-httpclientUbuntuhirsute*
Commons-httpclientUbuntuimpish*
Commons-httpclientUbuntujammy*
Commons-httpclientUbuntuprecise*
Commons-httpclientUbuntutrusty*
Commons-httpclientUbuntutrusty/esm*
Commons-httpclientUbuntuvivid*
Commons-httpclientUbuntuwily*
Commons-httpclientUbuntuxenial*
Commons-httpclientUbuntuyakkety*
Commons-httpclientUbuntuzesty*
Httpcomponents-clientUbuntuesm-infra-legacy/trusty*
Httpcomponents-clientUbuntutrusty*
Httpcomponents-clientUbuntutrusty/esm*
Httpcomponents-clientUbuntuupstream*
Httpcomponents-clientUbuntuvivid*

References