CVE-2015-5262 PUBLISHED

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

EPSS 0.92% · 75.8th percentile

Risk Scores

EPSS Score
0.92%
75.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTShttpcomponents-client4.3.3-1, 4.3.3-1ubuntu0.1, 0
Ubuntu:16.04:LTScommons-httpclient0
Ubuntu:14.04:LTScommons-httpclient3.1-10.2, 0

Timeline

References

Open in Interactive Console →