drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Jackson
Name: |
Mehrere Probleme in Jackson |
|
ID: |
USN-4741-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS |
|
Datum: |
Do, 18. Februar 2021, 23:59 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10172
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15095
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7525 |
|
Applikationen: |
Jackson |
|
Originalnachricht |
--===============8778025035674002550== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="nbnxmx2qh4pyrmo3" Content-Disposition: inline
--nbnxmx2qh4pyrmo3 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-4741-1 February 18, 2021
libjackson-json-java vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Jackson could be made to crash if it opened a specially crafted file.
Software Description: - libjackson-json-java: Suite of data-processing tools for Java
Details:
It was discovered that Jackson Databind incorrectly handled deserialization. An attacker could possibly use this issue to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS: libjackson-json-java 1.9.2-7ubuntu0.2
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/4741-1 CVE-2017-15095, CVE-2017-7525, CVE-2019-10172
Package Information: https://launchpad.net/ubuntu/+source/libjackson-json-java/1.9.2-7ubuntu0.2
--nbnxmx2qh4pyrmo3 Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEkCdEQ5T6DutSveCybUp5kL3izGYFAmAu6sQACgkQbUp5kL3i zGa74A//VnY4sKsZrWUeut1Lvde8DTtwUQ6tkH088EufpkE/MNva0rLua8HOR5BB foK7i7z66kL43qbFV737JKSxn80Pd2RbyCSgs4TIN8dJT6Guk37iRLvy1/MJDddK jo73Z0nEzlyDn4IC+0vXXvvQFLNXam05z719aucyEkK8nurBSmcBYttB1iG2u1a1 +YxQrYmL36gE03X9vUn/MhoGLzUd4TNTsRuzftVktoK9inadD8ZbwwcuUj9bVMBA rBde4OLVm6xjchbdpXbBT9L5av+UHsAib1eBMPi+PTR7yL6IGtPOILNjgiIeoRm8 UC1GjYEaPwb7+O+IjIVeRrWTlcIZFbZE7q0iwiyVOlOkgfpk9NqE6gMo30ZHgr+U 7Wol2N2byeaLySh5toBDTE0ZCa2il90f3zIN/yA4ZXRpaif1AumtFSxxF9aSFJe/ 9J++5PPoP4bbGU7QIpnkQlZZcSVN/9khkXbndPXA296QYjfyNvNLpgo+4fRXEjpM 4s/KmHqXXfpvyrLiJ8YRJP4+yUpb+RiWzSqwZ+rKESgcqFb+bcvMteeC1SRG9rF2 KZS5nmYyjsatVt5jHOxKlLZ+cc8O/jNWqhJ4nrFGOudLEMrpiewoZbr0cJfGUNZ6 ZJIAz0f8+9Xqfev3YiuqnFizFQn6caoiraImB6fg5YCUHmsFnP4= =kSVD -----END PGP SIGNATURE-----
--nbnxmx2qh4pyrmo3--
--===============8778025035674002550== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|