Описание
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| groovy | fixed | 2.4.6-1 | package | |
| groovy | fixed | 1.8.6-4+deb8u1 | jessie | package |
| groovy | fixed | 1.8.6-1+deb7u1 | wheezy | package |
| groovy2 | fixed | 2.2.2+dfsg-5 | package | |
| groovy2 | fixed | 2.2.2+dfsg-3+deb8u1 | jessie | package |
Связанные уязвимости
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy