Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-5227-1 Moderate: Gson Java Library De-serialization Flaw

debian
Calendar Grey September 7, 2022
Debian Logo
Safeguard your software systems. Apply the latest security patch for Gson to mitigate potential exploitation threats.
It was discovered that Gson, a Java library that can be used to convert Java Objects into their JSON representations and vice versa, was vulnerable to a de- serialization flaw

Summary

It was discovered that Gson, a Java library that can be used to convert Java
Objects into their JSON representations and vice versa, was vulnerable to a de-
serialization flaw. An application would de-serialize untrusted data without
sufficiently verifying that the resulting data will be valid, letting the
attacker to control the state or the flow of the execution. This can lead to a
denial of service or even the execution of arbitrary code.

For the stable distribution (bullseye), this problem has been fixed in
version 2.8.6-1+deb11u1.

We recommend that you upgrade your libgoogle-gson-java packages.

For the detailed security status of libgoogle-gson-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libgoogle-gson-java

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: libgoogle-gson-java
CVE ID: CVE-2022-25647

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here