Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Hibernate
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Hibernate
ID: USN-6845-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
Datum: Mo, 24. Juni 2024, 23:15
Referenzen: https://launchpad.net/ubuntu/+source/libhibernate3-java/3.6.10.Final-9+deb10u1build0.20.04.1
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25638
Applikationen: Hibernate

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2700141735863638171==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------uYlyOBbC0wM10ePUC0LwOtnd"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------uYlyOBbC0wM10ePUC0LwOtnd
Content-Type: multipart/mixed;
boundary="------------fhRbvhSToNaXrXZU0nba0HVM";
protected-headers="v1"
From: Amir Naseredini <amir.naseredini@canonical.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <f0d7216a-7ebf-458d-8dff-ed1747277292@canonical.com>
Subject: [USN-6845-1] Hibernate vulnerability

--------------fhRbvhSToNaXrXZU0nba0HVM
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-6845-1
June 24, 2024

libhibernate3-java vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Hibernate could be made to expose sensitive information.

Software Description:
- libhibernate3-java: Relational Persistence for Idiomatic Java

Details:

It was discovered that Hibernate incorrectly handled certain inputs with
unsanitized literals. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
libhibernate3-java 3.6.10.Final-9+deb10u1build0.20.04.1

Ubuntu 18.04 LTS
libhibernate3-java 3.6.10.Final-9ubuntu0.18.04.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libhibernate3-java 3.6.10.Final-4ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6845-1
CVE-2020-25638

Package Information:

https://launchpad.net/ubuntu/+source/libhibernate3-java/3.6.10.Final-9+deb10u1build0.20.04.1
--------------fhRbvhSToNaXrXZU0nba0HVM--

--------------uYlyOBbC0wM10ePUC0LwOtnd
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmZ5bf8FAwAAAAAACgkQVjg+NdFTuLJm
YAv+IgVa4CUSAFY11JMjCpSfdChb3Id1sd1euZUX0exZR5wc279cGaG7Cp7aBoG+bOPwgWpiWo89
8cPUdpPH2KJru5FSNOfuMJRHTBJ/DnhHcHIYZecVtkEYbgle5gwbXAmQ8lVki30aqih9i19MWdSR
w65I0ltJjaefB0FR37nM8ehl8KR8FZVXw57p9xlhVu6lSSiH4JLIXv+1DsDQSQwzfPs/hZu+60iY
vfPoOl6d+0HIwSzwoxSJm/rPdQ8/lSiR65C1pDSyx+wFGFuxO0R8csRrieWasVl+N+1VzLqdnSd3
tDv09N1u97ajFpko+GMkd4sksLGBgqi4iQcq/eVQIZjF5KVcPBWgNFYdUx8jo8ENKKNDtmnXzTEJ
jnXVKIw6/SIW88mPW5++EvWw7VeV9uEevFg1udEoCiPA9nzMzSj2j6EVhPC5qfkNnPeYYmZtQEYS
vyWJ42RS73LBSSh4sDP7jTi66qNWjv8vaqiyA7s/tQbrkNTaGNdeNT3qYQvO
=lXWo
-----END PGP SIGNATURE-----

--------------uYlyOBbC0wM10ePUC0LwOtnd--


--===============2700141735863638171==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============2700141735863638171==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung