Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-0592

Опубликовано: 26 мар. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-0592: slf4j security update (IMPORTANT)

[0:1.7.4-4]

  • Disallow EventData deserialization by default (CVE-2018-8088)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

slf4j

1.7.4-4.el7_4

slf4j-javadoc

1.7.4-4.el7_4

slf4j-manual

1.7.4-4.el7_4

Oracle Linux x86_64

slf4j

1.7.4-4.el7_4

slf4j-javadoc

1.7.4-4.el7_4

slf4j-manual

1.7.4-4.el7_4

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

CVSS3: 8.1
redhat
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

CVSS3: 9.8
nvd
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

CVSS3: 9.8
debian
больше 7 лет назад

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before ...

suse-cvrf
больше 7 лет назад

Security update for slf4j