Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian LTS: DLA-2030-1 Critical: jackson-databind Code Execution Risk

debian lts
Calendar Grey December 10, 2019
Dist Debian Esm H88
Recent research highlights significant security flaws in Jackson Databind on Debian that could allow deserialization attacks and remote code execution. Immediate upgrades are recommended!
More deserialization flaws were discovered in jackson-databind which could allow an unauthenticated user to perform remote code execution

Summary

We recommend that you upgrade your jackson-databind packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: jackson-databind
Version: 2.4.2-2+deb8u10
CVE ID: CVE-2019-17267 CVE-2019-17531

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here