Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-0162

Опубликовано: 19 янв. 2021
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2021-0162: xstream security update (IMPORTANT)

[1.3.1-12]

  • Rebuild with OpenJDK 7

[1.3.1-11]

  • Fix remote code execution vulnerability
  • Resolves: CVE-2020-26217

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

xstream

1.3.1-12.el7_9

xstream-javadoc

1.3.1-12.el7_9

Oracle Linux x86_64

xstream

1.3.1-12.el7_9

xstream-javadoc

1.3.1-12.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 8
ubuntu
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 9
redhat
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
nvd
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
debian
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...

CVSS3: 8
github
около 5 лет назад

XStream can be used for Remote Code Execution