=========================================================================Ubuntu Security Notice USN-4575-1
October 13, 2020

dom4j vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

dom4j could be made to expose sensitive information or run programs if it
received specially crafted input.

Software Description:
- dom4j: Flexible XML framework for Java

Details:

It was discovered that dom4j incorrectly handled reading XML data. A
remote attacker could exploit this with a crafted XML file to expose
sensitive data or possibly execute arbitrary code. (CVE-2020-10683)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libdom4j-java                   1.6.1+dfsg.3-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4575-1
  CVE-2020-10683

Package Information:
  https://launchpad.net/ubuntu/+source/dom4j/1.6.1+dfsg.3-2ubuntu1.1


Ubuntu 4575-1: dom4j vulnerability

October 13, 2020
dom4j could be made to expose sensitive information or run programs if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libdom4j-java 1.6.1+dfsg.3-2ubuntu1.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4575-1

CVE-2020-10683

Severity
October 13, 2020

Package Information

https://launchpad.net/ubuntu/+source/dom4j/1.6.1+dfsg.3-2ubuntu1.1

Related News