Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:3476-1

Опубликовано: 20 окт. 2021
Источник: suse-cvrf

Описание

Security update for xstream

This update for xstream fixes the following issues:

  • Upgrade to 1.4.18
  • CVE-2021-39139: Fixed an issue that allowed an attacker to execute arbitrary code execution by manipulating the processed input stream with type information. (bsc#1189798)
  • CVE-2021-39140: Fixed an issue that allowed an attacker to execute a DoS attack by manipulating the processed input stream. (bsc#1189798)
  • CVE-2021-39141: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39144: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39145: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39146: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39147: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39148: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39149: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39150: Fixed an issue that allowed an attacker to access protected resources hosted within the intranet or in the host itself. (bsc#1189798)
  • CVE-2021-39151: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39152: Fixed an issue that allowed an attacker to access protected resources hosted within the intranet or in the host itself. (bsc#1189798)
  • CVE-2021-39153: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)
  • CVE-2021-39154: Fixed an issue that allowed an attacker to achieve arbitrary code execution. (bsc#1189798)

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
xstream-1.4.18-3.14.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
xstream-1.4.18-3.14.1
Image server-image
xstream-1.4.18-3.14.1
SUSE Linux Enterprise Module for Development Tools 15 SP2
xstream-1.4.18-3.14.1
SUSE Linux Enterprise Module for Development Tools 15 SP3
xstream-1.4.18-3.14.1
SUSE Manager Server Module 4.1
xstream-1.4.18-3.14.1
SUSE Manager Server Module 4.2
xstream-1.4.18-3.14.1

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario can be adjusted easily to an external Xalan that works regardless of the version of the Java runtime. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки

Описание

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:xstream-1.4.18-3.14.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:xstream-1.4.18-3.14.1

Ссылки
Уязвимость SUSE-SU-2021:3476-1