Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DLA-2705-1 Moderate: Libxml2 Remote Code Execution Vulnerability

debian lts
Calendar Grey July 5, 2021
Dist Debian Esm H88
The latest Debian LTS Advisory DLA-2704-1 highlights a vulnerability in libxstream-java that permits remote command execution by malicious actors.
A vulnerability in XStream, a Java library to serialize objects to and from XML, may allow a remote attacker to execute commands of the host only by manipulating the processed inpu...

Summary

Note: the XStream project recommends to setup its security framework
with a whitelist limited to the minimal required types, rather than
relying on the black list (which got updated to address this
vulnerability). The project is also phasing out maintainance of the
black list, see https://x-stream.github.io/security.html .

For Debian 9 stretch, this problem has been fixed in version
1.4.11.1-1+deb9u3.

We recommend that you upgrade your libxstream-java packages.

For the detailed security status of libxstream-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxstream-java

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: libxstream-java
Version: 1.4.11.1-1+deb9u3
CVE ID: CVE-2021-29505
Debian Bug: 989491

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here