• [SECURITY] [DSA 4004-1] jackson-databind security update

    From Sebastien Delafond@1:229/2 to All on Fri Oct 20 08:00:01 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4004-1 [email protected] https://www.debian.org/security/ Sebastien Delafond October 20, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : jackson-databind
    CVE ID : CVE-2017-7525
    Debian Bug : 870848

    Liao Xinxi discovered that jackson-databind, a Java library used to
    parse JSON and other data formats, did not properly validate user
    input before attemtping deserialization. This allowed an attacker to
    perform code execution by providing maliciously crafted input.

    For the oldstable distribution (jessie), this problem has been fixed
    in version 2.4.2-2+deb8u1.

    For the stable distribution (stretch), this problem has been fixed in
    version 2.8.6-1+deb9u1.

    We recommend that you upgrade your jackson-databind packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlnpjfIACgkQEL6Jg/PV nWRpNgf/Qr9B9O5J6JfcQIZV2j0gFEtskjYjzw0Mus+TC1IMFHOLRcKMD4O0FgGO IY8IPrBoefyvYxwwZNVCY86yo21uiMNAqmAnJBBpt0t7GCViDyKDJNK+ksNH6Ey9 bjEF+Pck4Ku5bHXUEb0/W1u91I6dKye1wP4R3S8sUaGxlEDeVPJTfGtXTpe+oB+Y CO7J3XtzpaF4d83SFLmOCobWBe0zKWHvTu5PiJdSwJvhEPmFNkTrs2v8yhxmS8Gv K0kF8P8EdXS2pB5sxKV17nw0IIs+D3nVey1BitNkhhQ862ChlkgYMspjukcBuwHd W2/rMyC2JxiXyeT4w8CxNok2BHjKRg==
    =RuHf
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)