Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

Debian 11 LTS: DLA-4001-1 moderate: libxstream-java Denial of Service

debian lts
Calendar Grey December 21, 2024
Dist Debian Esm H88
Ubuntu Security Notice USN-5001-1 addresses vulnerabilities in libxstream-java. Users are urged to upgrade for improved protection.
XStream is a simple java library to serialize objects to XML and back again

Summary

CVE-2021-43859:

XStream can cause a Denial of Service (DoS) by injecting highly
recursive collections or maps

CVE-2024-47072

XStream was vulnerable to a Denial of Service attack due
to stack overflow from a manipulated binary input stream

For Debian 11 bullseye, this problem has been fixed in version
1.4.15-3+deb11u3.

We recommend that you upgrade your libxstream-java packages.

For the detailed security status of libxstream-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxstream-java

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: libxstream-java
Version: 1.4.15-3+deb11u3
CVE ID: CVE-2021-43859 CVE-2024-47072
Debian Bug: 1087274

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here