Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Fedora 31: FEDORA-2019-99ff6aa32c Moderate: jackson-bom RCE Vulnerability

fedora
Calendar Grey September 17, 2019
Dist Fedora Esm H88
Keep abreast of Fedora's recent patch for jackson-bom, which tackles multiple serious vulnerabilities linked to remote code execution.
- Update jackson-databind to version 2.9.9.3

Summary

A "bill of materials" POM for Jackson dependencies.

- Update jackson-databind to version 2.9.9.3. - Update jackson-core to version

2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to

version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814,

CVE-2019-14379, and CVE-14439.

[ 1 ] Bug #1737518 - CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1737518

[ 2 ] Bug #1725808 - CVE-2019-12384 jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1725808

[ 3 ] Bug #1725796 - CVE-2019-12814 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1725796

[ 4 ] Bug #1713469 - CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1713469

[ 5 ] Bug #1752964 - CVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDI [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1752964

su -c 'dnf upgrade --advisory FEDORA-2019-99ff6aa32c' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 2.9.9
Release: 1.fc31
Summary: Bill of materials POM for Jackson projects

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here