Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: DSA-5300-1 Important: GnuTLS Buffer Overflow Vulnerability

debian
Calendar Grey November 28, 2022
Debian Logo
To mitigate remote code execution threats on Debian systems, update the commons-configuration2 package by checking the version, upgrading it, and verifying the changes
Apache Commons Configuration, a Java library providing a generic configuration interface, performs variable interpolation, allowing properties to be dynamically evaluated and expan...

Summary

Apache Commons Configuration, a Java library providing a generic configuration
interface, performs variable interpolation, allowing properties to be
dynamically evaluated and expanded. Starting with version 2.4 and continuing
through 2.7, the set of default Lookup instances included interpolators that
could result in arbitrary code execution or contact with remote servers. These
lookups are: - "script" - execute expressions using the JVM script execution
engine (javax.script) - "dns" - resolve dns records - "url" - load values from
urls, including from remote server applications using the interpolation
defaults in the affected versions may be vulnerable to remote code execution or
unintentional contact with remote servers if untrusted configuration values are
used.

For the stable distribution (bullseye), this problem has been fixed in
version 2.8.0-1~deb11u1.

We recommend that you upgrade your commons-configuration2 packages.

For the detailed security status of commons-configuration2 please refer to
...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: commons-configuration2
CVE ID: CVE-2022-33980

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here