CVE-2021-43859:
XStream can cause a Denial of Service (DoS) by injecting highly
recursive collections or maps
CVE-2024-47072
XStream was vulnerable to a Denial of Service attack due
to stack overflow from a manipulated binary input stream
For Debian 11 bullseye, this problem has been fixed in version
1.4.15-3+deb11u3.
We recommend that you upgrade your libxstream-java packages.
For the detailed security status of libxstream-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxstream-java
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
Get the latest Linux and open source security news straight to your inbox.