{"id":"MGASA-2015-0212","summary":"Updated async-http-client packages fix security vulnerabilities","details":"Updated async-http-client packages fix security vulnerabilities:\n\nIt was found that async-http-client would disable SSL/TLS certificate\nverification under certain conditions, for example if HTTPS communication also\nuses client certificates. This can be exploited by a Man-in-the-middle (MITM)\nattack where the attacker can spoof a valid certificate (CVE-2013-7397).\n\nIt was found that async-http-client did not verify that the server hostname\nmatched the domain name in the subject's Common Name (CN) or subjectAltName\nfield in X.509 certificates. This could allow a man-in-the-middle attacker to\nspoof an SSL server if they had a certificate that was valid for any domain\nname (CVE-2013-7398).\n","modified":"2026-04-16T06:22:33.579974453Z","published":"2015-05-11T20:10:38Z","upstream":["CVE-2013-7397","CVE-2013-7398"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0212.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15887"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2015-May/157337.html"}],"affected":[{"package":{"name":"async-http-client","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/async-http-client?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.22-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0212.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}