[Git][security-tracker-team/security-tracker][master] CVE-2017-7525 and CVE-2017-15095 are also in libjackson-json-java
Adrian Bunk
bunk at debian.org
Sat Nov 30 20:20:05 GMT 2019
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d2027093 by Adrian Bunk at 2019-11-30T20:19:46Z
CVE-2017-7525 and CVE-2017-15095 are also in libjackson-json-java
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -119757,6 +119757,7 @@ CVE-2017-15096 (A flaw was found in GlusterFS in versions prior to 3.10. A null
CVE-2017-15095 (A deserialization flaw was discovered in the jackson-databind in versi ...)
{DSA-4037-1}
- jackson-databind 2.9.1-1
+ - libjackson-json-java <unfixed>
NOTE: The Debian upload for stretch (2.8.6-1+deb9u1) and jessie (2.4.2-2+deb8u1)
NOTE: misses the further sets of blacklists, in particular as well
NOTE: https://github.com/FasterXML/jackson-databind/commit/3bfbb835
@@ -119771,6 +119772,8 @@ CVE-2017-15095 (A deserialization flaw was discovered in the jackson-databind in
NOTE: NO_DESER_CLASS_NAMES as of:
NOTE: https://github.com/FasterXML/jackson-databind/blob/7093008aa2afe8068e120df850189ae072dfa1b2/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java#L43
NOTE: Details: http://www.openwall.com/lists/oss-security/2017/11/02/3
+ NOTE: For libjackson-json-java:
+ NOTE: https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
CVE-2017-15094 (An issue has been found in the DNSSEC parsing code of PowerDNS Recurso ...)
- pdns-recursor 4.0.7-1
[stretch] - pdns-recursor 4.0.4-1+deb9u2
@@ -143019,10 +143022,13 @@ CVE-2017-7526 (libgcrypt before version 1.7.8 is vulnerable to a cache side-chan
CVE-2017-7525 (A deserialization flaw was discovered in the jackson-databind, version ...)
{DSA-4004-1}
- jackson-databind 2.9.1-1 (bug #870848)
+ - libjackson-json-java <unfixed>
NOTE: https://github.com/FasterXML/jackson-databind/issues/1599
CVE-2017-7524 (tpm2-tools versions before 1.1.1 are vulnerable to a password leak due ...)
- tpm2-tools 2.1.0-1 (bug #866257)
NOTE: https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d69985157
+ NOTE: For libjackson-json-java:
+ NOTE: https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
CVE-2017-7523 (Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buff ...)
NOT-FOR-US: Cygwin
CVE-2017-7522 (OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191130/26c261c9/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list