CVE-2015-5262

Aliases:GHSA-fmj5-wv96-r2ch
Modified
Published: 27 Oct 2015, 16:00
Last modified:06 Aug 2024, 06:41

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
1.2% LOW
1% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Oct 2015, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 06:41
Last Modified
Vulnerability information updated

Description

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.20% Percentile: 79%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • apachehttpclient

    ≥ 4.3, ≤ 4.3.5

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04

  • fedoraprojectfedora

    21 | 22 | 23

  • org.apache.httpcomponentshttpclient

    < 4.3.6

References (21)