Total vulnerabilities in the database
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Software | From | Fixed in |
---|---|---|
fedoraproject / fedora | 22 | 22.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
fedoraproject / fedora | 23 | 23.x |
fedoraproject / fedora | 21 | 21.x |
canonical / ubuntu_linux | 15.04 | 15.04.x |
apache / httpclient | 4.3 | 4.3.5.x |
![]() |
- | 4.3.6 |