Name : async-http-client Product : Fedora 20 Version : 1.7.22 Release : 2.fc20 URL : https://github.com/AsyncHttpClient/async-http-client Summary : Asynchronous Http Client for Java Description : Async Http Client library purpose is to allow Java applications to easily execute HTTP requests and asynchronously process the HTTP responses. The Async HTTP Client library is simple to use.
Security fix for CVE-2013-7398, CVE-2013-7397 ------------------------------------------------------------------------------- - ChangeLog:
* Fri Apr 24 2015 Michal Srb <msrb@redhat.com> - 1.7.22-2 - Resolves: CVE-2013-7397 - Resolves: CVE-2013-7398 * Wed Dec 4 2013 Mikolaj Izdebski <mizdebsk@redhat.com> - 1.7.22-1 - Update to upstream version 1.7.22 * Fri Oct 18 2013 Michal Srb <msrb@redhat.com> - 1.7.21-1 - Update to upstream version 1.7.21 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1133773 - CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates https://bugzilla.redhat.com/show_bug.cgi?id=1133773 [ 2 ] Bug #1133769 - CVE-2013-7397 async-http-client: SSL/TLS certificate verification is disabled under certain conditions https://bugzilla.redhat.com/show_bug.cgi?id=1133769 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update async-http-client' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.