Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DLA-2616-1 Critical: libxstream-java Remote Execution Risk

debian lts
Calendar Grey April 3, 2021
Dist Debian Esm H88
An important patch for libxstream-java tackles the vulnerabilities linked to remote code execution. All users are advised to apply this update promptly.
In XStream there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream

Summary

For Debian 9 stretch, these problems have been fixed in version
1.4.11.1-1+deb9u2.

We recommend that you upgrade your libxstream-java packages.

For the detailed security status of libxstream-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxstream-java

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: libxstream-java
Version: 1.4.11.1-1+deb9u2
CVE ID: CVE-2021-21341 CVE-2021-21342 CVE-2021-21343 CVE-2021-21344
Debian Bug: 985843

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here