Bug 27389 - httpcomponents-client new security issue CVE-2020-13956
Summary: httpcomponents-client new security issue CVE-2020-13956
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-10-11 18:25 CEST by David Walser
Modified: 2021-07-07 01:13 CEST (History)
5 users (show)

See Also:
Source RPM: httpcomponents-client-4.5.10-1.mga8.src.rpm
CVE: CVE-2020-13956
Status comment:


Attachments

Description David Walser 2020-10-11 18:25:12 CEST
A security issue in the Apache HttpClient has been announced on October 8:
https://www.openwall.com/lists/oss-security/2020/10/08/4

The issue is fixed upstream in 4.5.12.

Also likely affected is the old jakarta-commons-httpclient which should have been dropped a long time ago (see Bug 18700).

Mageia 7 is also affected.
David Walser 2020-10-11 18:25:20 CEST

Whiteboard: (none) => MGA7TOO

Comment 1 David Walser 2020-10-13 18:11:57 CEST
Debian-LTS has issued an advisory for this on October 10:
https://www.debian.org/lts/security/2020/dla-2405
Comment 2 David Walser 2020-10-15 19:01:20 CEST
Debian has issued an advisory for this on October 14:
https://www.debian.org/security/2020/dsa-4772
Comment 3 Nicolas Lécureuil 2020-12-27 11:28:24 CET
Fix pushed in mageia cauldron

Whiteboard: MGA7TOO => (none)
CC: (none) => mageia
Version: Cauldron => 7

Comment 4 Nicolas Lécureuil 2020-12-27 11:31:17 CET
fix pushed in maga7:
src:
    httpcomponents-client-4.5.5-1.1.mga7

Assignee: java => qa-bugs

Comment 5 David Walser 2020-12-27 17:08:11 CET
Saving advisory, but assigning back to Java team for jakarta-commons-httpclient which hasn't been fixed (Mageia 7) and dropped (Cauldron) yet.

Advisory:
========================

Updated httpcomponents-client packages fix security vulnerability:

Priyank Nigam discovered that HttpComponents Client could misinterpret
malformed authority component in a request URI and pick the wrong target host
for request execution (CVE-2020-13956).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13956
https://www.debian.org/security/2020/dsa-4772
========================

Updated packages in core/updates_testing:
========================
httpcomponents-client-4.5.5-1.1.mga7
httpcomponents-client-cache-4.5.5-1.1.mga7
httpcomponents-client-javadoc-4.5.5-1.1.mga7

from httpcomponents-client-4.5.5-1.1.mga7.src.rpm

Whiteboard: (none) => MGA7TOO
Assignee: qa-bugs => java
Version: 7 => Cauldron

David Walser 2020-12-27 21:01:01 CET

Status comment: (none) => jakarta-commons-httpclient also needs to be addressed

Comment 6 Nicolas Lécureuil 2020-12-27 22:32:37 CET
i don't think  jakarta-commons-httpclient is affected.
We don't plan to drop jakarta-commons-httpclient yet.
Comment 7 David Walser 2020-12-27 22:39:53 CET
(In reply to Nicolas Lécureuil from comment #6)
> i don't think  jakarta-commons-httpclient is affected.

Do you have any basis for that?  They are based on the same code.  See Bug 13932 and Bug 16870, for instance.

> We don't plan to drop jakarta-commons-httpclient yet.

It should have been dropped a long time ago, but I know Fedora needs to help us with that.
Comment 8 Nicolas Lécureuil 2020-12-28 09:38:34 CET
there is still fop using it, we need to get rid of this package in fop first.
if time allows we can work on it
Comment 9 Nicolas Lécureuil 2020-12-28 18:39:44 CET
i remove the deps from fop
Comment 10 Nicolas Lécureuil 2021-01-01 23:51:55 CET
jakarta-commons-httpclient is not in cauldron anymore

Whiteboard: MGA7TOO => (none)

Nicolas Lécureuil 2021-01-01 23:52:20 CET

Version: Cauldron => 7

Comment 11 David Walser 2021-01-01 23:58:28 CET
(In reply to Nicolas Lécureuil from comment #10)
> jakarta-commons-httpclient is not in cauldron anymore

Thanks.  Please see my note in the other bug:
https://bugs.mageia.org/show_bug.cgi?id=18700#c7
Comment 12 David Walser 2021-06-29 01:30:39 CEST
Doesn't look like jakarta-commons-httpclient contains the affected code.

Advisory in Comment 5.

Status comment: jakarta-commons-httpclient also needs to be addressed => (none)
Assignee: java => qa-bugs

Comment 13 Herman Viaene 2021-07-05 16:44:11 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref bug 16870 for decision to OK on clean install.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 14 Thomas Andrews 2021-07-05 18:36:52 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Aurelien Oudelet 2021-07-05 20:40:22 CEST

CVE: (none) => CVE-2020-13956
Keywords: (none) => advisory
CC: (none) => ouaurelien

Comment 15 Mageia Robot 2021-07-07 01:13:40 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0314.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.