Following bug 520200 and version bump of httpcomponents-core, we need to version bump httpcomponentns-client to its latest iteration. Sec team will ask up to clean up vulnerable versions after stabilisation will be done. As far as httpcomponents-client-4.3.1 go, it doesn't build against 4.4. Which means it is a blocking bug. Reproducible: Always
+*httpcomponents-client-4.5 (24 Jun 2015) + + 24 Jun 2015; Patrice Clement <monsieurp@gentoo.org> + +files/httpcomponents-client-fluent-hc-4.5-build.xml, + +files/httpcomponents-client-httpclient-4.5-build.xml, + +files/httpcomponents-client-httpclient-cache-4.5-build.xml, + +files/httpcomponents-client-httpclient-osgi-4.5-build.xml, + +files/httpcomponents-client-httpmime-4.5-build.xml, + +httpcomponents-client-4.5.ebuild: + Version bump. Fix bug 552566. + Phew! Arch teams, This is an urgent request. We need to clean up httpcomponents-client-4.3.1-r1 since it has a dependency on a vulnerable version of httpcomponents-core. Please stabilise: =dev-java/httpcomponents-client-4.5.ebuild Target arches: amd64 x86 Thanks!
amd64 stable
x86 stable. Closing.