Описание
Security update for slf4j
This update for slf4j fixes the following security issue:
- CVE-2018-8088: Remote attackers could have bypassed intended access restrictions via crafted data. Disallow EventData deserialization by default from now on (bsc#1085970).
Список пакетов
openSUSE Leap 15.0
slf4j-1.7.12-lp150.4.3.1
slf4j-javadoc-1.7.12-lp150.4.3.1
slf4j-manual-1.7.12-lp150.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2018:1625-1
- SUSE Security Ratings
Описание
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data.
Затронутые продукты
openSUSE Leap 15.0:slf4j-1.7.12-lp150.4.3.1
openSUSE Leap 15.0:slf4j-javadoc-1.7.12-lp150.4.3.1
openSUSE Leap 15.0:slf4j-manual-1.7.12-lp150.4.3.1
Ссылки
- CVE-2018-8088
- SUSE Bug 1085970