Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Debian 8: DLA-2091-1 Moderate: libjackson-json-java Security Update

debian lts
Calendar Grey January 31, 2020
Dist Debian Esm H88
Remedies for libjackson-json-java security flaws, notably CVE-2017-7525, improving Debian LTS protection.
Several vulnerabilities were fixed in libjackson-json-java

Summary

CVE-2017-7525

Jackson Deserializer security vulnerability.

CVE-2017-15095

Block more JDK types from polymorphic deserialization.

CVE-2019-10172

XML external entity vulnerabilities.

For Debian 8 "Jessie", these problems have been fixed in version
1.9.2-3+deb8u1.

We recommend that you upgrade your libjackson-json-java packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: libjackson-json-java
Version: 1.9.2-3+deb8u1
CVE ID: CVE-2017-7525 CVE-2017-15095 CVE-2019-10172

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here