it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Sebastien Delafond <seb AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4004-1] jackson-databind security update
- Date: Fri, 20 Oct 2017 05:52:40 +0000
- List-archive: https://lists.debian.org/msgid-search/E1e5QEa-0006Rw-Va AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-return-path: <seb AT seger.debian.org>
- Priority: urgent
- Resent-date: Fri, 20 Oct 2017 05:52:57 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <7URW78NoiEO.A.m-E.58Y6ZB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4004-1 security AT debian.org
https://www.debian.org/security/ Sebastien Delafond
October 20, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : jackson-databind
CVE ID : CVE-2017-7525
Debian Bug : 870848
Liao Xinxi discovered that jackson-databind, a Java library used to
parse JSON and other data formats, did not properly validate user
input before attemtping deserialization. This allowed an attacker to
perform code execution by providing maliciously crafted input.
For the oldstable distribution (jessie), this problem has been fixed
in version 2.4.2-2+deb8u1.
For the stable distribution (stretch), this problem has been fixed in
version 2.8.6-1+deb9u1.
We recommend that you upgrade your jackson-databind packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlnpjfIACgkQEL6Jg/PV
nWRpNgf/Qr9B9O5J6JfcQIZV2j0gFEtskjYjzw0Mus+TC1IMFHOLRcKMD4O0FgGO
IY8IPrBoefyvYxwwZNVCY86yo21uiMNAqmAnJBBpt0t7GCViDyKDJNK+ksNH6Ey9
bjEF+Pck4Ku5bHXUEb0/W1u91I6dKye1wP4R3S8sUaGxlEDeVPJTfGtXTpe+oB+Y
CO7J3XtzpaF4d83SFLmOCobWBe0zKWHvTu5PiJdSwJvhEPmFNkTrs2v8yhxmS8Gv
K0kF8P8EdXS2pB5sxKV17nw0IIs+D3nVey1BitNkhhQ862ChlkgYMspjukcBuwHd
W2/rMyC2JxiXyeT4w8CxNok2BHjKRg==
=RuHf
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4004-1] jackson-databind security update, Sebastien Delafond, 20.10.2017
Archiv bereitgestellt durch MHonArc 2.6.19.