Adrian Bunk pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d2027093 by Adrian Bunk at 2019-11-30T20:19:46Z
CVE-2017-7525 and CVE-2017-15095 are also in libjackson-json-java

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -119757,6 +119757,7 @@ CVE-2017-15096 (A flaw was found in GlusterFS in 
versions prior to 3.10. A null
 CVE-2017-15095 (A deserialization flaw was discovered in the jackson-databind 
in versi ...)
        {DSA-4037-1}
        - jackson-databind 2.9.1-1
+       - libjackson-json-java <unfixed>
        NOTE: The Debian upload for stretch (2.8.6-1+deb9u1) and jessie 
(2.4.2-2+deb8u1)
        NOTE: misses the further sets of blacklists, in particular as well
        NOTE: https://github.com/FasterXML/jackson-databind/commit/3bfbb835
@@ -119771,6 +119772,8 @@ CVE-2017-15095 (A deserialization flaw was discovered 
in the jackson-databind in
        NOTE: NO_DESER_CLASS_NAMES as of:
        NOTE: 
https://github.com/FasterXML/jackson-databind/blob/7093008aa2afe8068e120df850189ae072dfa1b2/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java#L43
        NOTE: Details: http://www.openwall.com/lists/oss-security/2017/11/02/3
+       NOTE: For libjackson-json-java:
+       NOTE: 
https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
 CVE-2017-15094 (An issue has been found in the DNSSEC parsing code of PowerDNS 
Recurso ...)
        - pdns-recursor 4.0.7-1
        [stretch] - pdns-recursor 4.0.4-1+deb9u2
@@ -143019,10 +143022,13 @@ CVE-2017-7526 (libgcrypt before version 1.7.8 is 
vulnerable to a cache side-chan
 CVE-2017-7525 (A deserialization flaw was discovered in the jackson-databind, 
version ...)
        {DSA-4004-1}
        - jackson-databind 2.9.1-1 (bug #870848)
+       - libjackson-json-java <unfixed>
        NOTE: https://github.com/FasterXML/jackson-databind/issues/1599
 CVE-2017-7524 (tpm2-tools versions before 1.1.1 are vulnerable to a password 
leak due ...)
        - tpm2-tools 2.1.0-1 (bug #866257)
        NOTE: 
https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d69985157
+       NOTE: For libjackson-json-java:
+       NOTE: 
https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31
 CVE-2017-7523 (Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable 
to buff ...)
        NOT-FOR-US: Cygwin
 CVE-2017-7522 (OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable 
to deni ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/d2027093b7f8a31ea376193b3d47a7a4707c0f86
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to