Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Fedora 27 FEDORA-2018-6e6f1003d6 Critical: XML-RPC Deserialization Issue

fedora
Calendar Grey June 2, 2018
Dist Fedora Esm H88
Critical updates for xmlrpc in Fedora 27 focus on addressing deserialization and XML external entity vulnerabilities.
Security fix for CVE-2016-5003, CVE-2016-5002

Summary

Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol

that uses XML over HTTP to implement remote procedure calls.

Apache XML-RPC was previously known as Helma XML-RPC. If you have code

using the Helma library, all you should have to do is change the import

statements in your code from helma.xmlrpc.* to org.apache.xmlrpc.*.

Security fix for CVE-2016-5003, CVE-2016-5002

* Fri May 18 2018 Michael Simacek - 1:3.1.3-20

- Disallow deserialization of tags by default

- Resolves CVE-2016-5003

- Disallow loading of external DTD

- Resolves CVE-2016-5002

* Fri Feb 9 2018 Fedora Release Engineering - 1:3.1.3-19

- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[ 1 ] Bug #1508123 - CVE-2016-5003 xmlrpc: Deserialization of untrusted Java object through tag

https://bugzilla.redhat.com/show_bug.cgi?id=1508123

[ 2 ] Bug #1508110 - CVE-2016-5002 xmlrpc: XML external entity vulnerability SSRF via a crafted DTD

https://bugzilla.redhat.com/show_bug.cgi?id=1508110

su -c 'dnf upgrade --advisory FEDORA-2018-6e6f1003d6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MB2KL7W5G3BJY65ISPO5YSV4IGBNWSMD/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 3.1.3
Release: 20.fc27
Summary: Java XML-RPC implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here