drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Preisgabe von Informationen in Hibernate
Name: |
Preisgabe von Informationen in Hibernate |
|
ID: |
USN-6845-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS |
|
Datum: |
Mo, 24. Juni 2024, 23:15 |
|
Referenzen: |
https://launchpad.net/ubuntu/+source/libhibernate3-java/3.6.10.Final-9+deb10u1build0.20.04.1
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25638 |
|
Applikationen: |
Hibernate |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============2700141735863638171== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------uYlyOBbC0wM10ePUC0LwOtnd"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------uYlyOBbC0wM10ePUC0LwOtnd Content-Type: multipart/mixed; boundary="------------fhRbvhSToNaXrXZU0nba0HVM"; protected-headers="v1" From: Amir Naseredini <amir.naseredini@canonical.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <f0d7216a-7ebf-458d-8dff-ed1747277292@canonical.com> Subject: [USN-6845-1] Hibernate vulnerability
--------------fhRbvhSToNaXrXZU0nba0HVM Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-6845-1 June 24, 2024
libhibernate3-java vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS
Summary:
Hibernate could be made to expose sensitive information.
Software Description: - libhibernate3-java: Relational Persistence for Idiomatic Java
Details:
It was discovered that Hibernate incorrectly handled certain inputs with unsanitized literals. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04 LTS libhibernate3-java 3.6.10.Final-9+deb10u1build0.20.04.1
Ubuntu 18.04 LTS libhibernate3-java 3.6.10.Final-9ubuntu0.18.04.1~esm1 Available with Ubuntu Pro
Ubuntu 16.04 LTS libhibernate3-java 3.6.10.Final-4ubuntu0.1~esm1 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-6845-1 CVE-2020-25638
Package Information: https://launchpad.net/ubuntu/+source/libhibernate3-java/3.6.10.Final-9+deb10u1build0.20.04.1 --------------fhRbvhSToNaXrXZU0nba0HVM--
--------------uYlyOBbC0wM10ePUC0LwOtnd Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmZ5bf8FAwAAAAAACgkQVjg+NdFTuLJm YAv+IgVa4CUSAFY11JMjCpSfdChb3Id1sd1euZUX0exZR5wc279cGaG7Cp7aBoG+bOPwgWpiWo89 8cPUdpPH2KJru5FSNOfuMJRHTBJ/DnhHcHIYZecVtkEYbgle5gwbXAmQ8lVki30aqih9i19MWdSR w65I0ltJjaefB0FR37nM8ehl8KR8FZVXw57p9xlhVu6lSSiH4JLIXv+1DsDQSQwzfPs/hZu+60iY vfPoOl6d+0HIwSzwoxSJm/rPdQ8/lSiR65C1pDSyx+wFGFuxO0R8csRrieWasVl+N+1VzLqdnSd3 tDv09N1u97ajFpko+GMkd4sksLGBgqi4iQcq/eVQIZjF5KVcPBWgNFYdUx8jo8ENKKNDtmnXzTEJ jnXVKIw6/SIW88mPW5++EvWw7VeV9uEevFg1udEoCiPA9nzMzSj2j6EVhPC5qfkNnPeYYmZtQEYS vyWJ42RS73LBSSh4sDP7jTi66qNWjv8vaqiyA7s/tQbrkNTaGNdeNT3qYQvO =lXWo -----END PGP SIGNATURE-----
--------------uYlyOBbC0wM10ePUC0LwOtnd--
--===============2700141735863638171== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============2700141735863638171==--
|
|
|
|