[Git][security-tracker-team/security-tracker][master] CVE-2017-7525 and CVE-2017-15095 are also in libjackson-json-java

Adrian Bunk bunk at debian.org
Sat Nov 30 20:20:05 GMT 2019



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2027093 by Adrian Bunk at 2019-11-30T20:19:46Z
CVE-2017-7525 and CVE-2017-15095 are also in libjackson-json-java

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -119757,6 +119757,7 @@ CVE-2017-15096 (A flaw was found in GlusterFS in versions prior to 3.10. A null
 CVE-2017-15095 (A deserialization flaw was discovered in the jackson-databind in versi ...)
 	{DSA-4037-1}
 	- jackson-databind 2.9.1-1
+	- libjackson-json-java <unfixed>
 	NOTE: The Debian upload for stretch (2.8.6-1+deb9u1) and jessie (2.4.2-2+deb8u1)
 	NOTE: misses the further sets of blacklists, in particular as well
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/3bfbb835
@@ -119771,6 +119772,8 @@ CVE-2017-15095 (A deserialization flaw was discovered in the jackson-databind in
 	NOTE: NO_DESER_CLASS_NAMES as of:
 	NOTE: https://github.com/FasterXML/jackson-databind/blob/7093008aa2afe8068e120df850189ae072dfa1b2/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java#L43
 	NOTE: Details: http://www.openwall.com/lists/oss-security/2017/11/02/3
+	NOTE: For libjackson-json-java:
+	NOTE: https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
 CVE-2017-15094 (An issue has been found in the DNSSEC parsing code of PowerDNS Recurso ...)
 	- pdns-recursor 4.0.7-1
 	[stretch] - pdns-recursor 4.0.4-1+deb9u2
@@ -143019,10 +143022,13 @@ CVE-2017-7526 (libgcrypt before version 1.7.8 is vulnerable to a cache side-chan
 CVE-2017-7525 (A deserialization flaw was discovered in the jackson-databind, version ...)
 	{DSA-4004-1}
 	- jackson-databind 2.9.1-1 (bug #870848)
+	- libjackson-json-java <unfixed>
 	NOTE: https://github.com/FasterXML/jackson-databind/issues/1599
 CVE-2017-7524 (tpm2-tools versions before 1.1.1 are vulnerable to a password leak due ...)
 	- tpm2-tools 2.1.0-1 (bug #866257)
 	NOTE: https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d69985157
+	NOTE: For libjackson-json-java:
+	NOTE: https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
 CVE-2017-7523 (Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buff ...)
 	NOT-FOR-US: Cygwin
 CVE-2017-7522 (OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191130/26c261c9/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list