Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7957

Опубликовано: 03 апр. 2017
Источник: redhat
CVSS3: 5.9

Описание

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.

It was found that XStream contains a vulnerability that allows a maliciously crafted file to be parsed successfully which could cause an application crash. The crash occurs if the file that is being fed into XStream input stream contains an instances of the primitive type 'void'. An attacker could use this flaw to create a denial of service on the target system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xstreamAffected
Red Hat Enterprise Linux 7xstreamAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proUnder investigation
Red Hat JBoss A-MQ 6camelAffected
Red Hat JBoss Data Grid 6xstreamWill not fix
Red Hat JBoss Data Grid 7xstreamAffected
Red Hat JBoss Fuse Service Works 6xstreamWill not fix
Red Hat JBoss Portal 6xstreamWill not fix
Red Hat JBoss SOA Platform 5xstreamWill not fix
Red Hat OpenShift Enterprise 2xstreamNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1441538XStream: DoS when unmarshalling void type

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.

CVSS3: 7.5
nvd
почти 9 лет назад

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.

CVSS3: 7.5
debian
почти 9 лет назад

XStream through 1.4.9, when a certain denyTypes workaround is not used ...

CVSS3: 7.5
github
больше 5 лет назад

Denial of service in XStream

5.9 Medium

CVSS3

Уязвимость CVE-2017-7957