Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 8 DLA-1943-1: Moderate RCE Patch for jackson-databind Package

debian lts
Calendar Grey October 2, 2019
Dist Debian Esm H88
To prevent deserialization vulnerabilities that risk remote code execution, upgrade the jackson-databind package on your Debian 8 system promptly
More deserialization flaws were discovered in jackson-databind relating to the classes in com.zaxxer.hikari.HikariConfig, com.zaxxer.hikari.HikariDataSource, commons-dbcp and com.p...

Summary

We recommend that you upgrade your jackson-databind packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: jackson-databind
Version: 2.4.2-2+deb8u9
CVE ID: CVE-2019-14540 CVE-2019-16335 CVE-2019-16942
Debian Bug: 940498 941530

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here