Axis could be made to crash or execute arbitrary code if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6470-1 November 02, 2023 axis vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Axis could be made to crash or execute arbitrary code if it received specially crafted input. Software Description: - axis: SOAP implementation in Java Details: It was discovered that Axis incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2023-40743) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libaxis-java 1.4-28+deb10u1build0.23.10.1 libaxis-java-doc 1.4-28+deb10u1build0.23.10.1 Ubuntu 23.04: libaxis-java 1.4-28+deb10u1build0.23.04.1 libaxis-java-doc 1.4-28+deb10u1build0.23.04.1 Ubuntu 22.04 LTS: libaxis-java 1.4-28+deb10u1build0.22.04.1 libaxis-java-doc 1.4-28+deb10u1build0.22.04.1 Ubuntu 20.04 LTS: libaxis-java 1.4-28+deb10u1build0.20.04.1 libaxis-java-doc 1.4-28+deb10u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libaxis-java 1.4-25ubuntu0.1~esm1 libaxis-java-doc 1.4-25ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libaxis-java 1.4-24ubuntu0.1~esm1 libaxis-java-doc 1.4-24ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: CVE-2023-40743 Package Information: https://launchpad.net/ubuntu/+source/axis/1.4-28+deb10u1build0.23.10.1 https://launchpad.net/ubuntu/+source/axis/1.4-28+deb10u1build0.23.04.1 https://launchpad.net/ubuntu/+source/axis/1.4-28+deb10u1build0.22.04.1 https://launchpad.net/ubuntu/+source/axis/1.4-28+deb10u1build0.20.04.1 . Vulnerability in Axis on Ubuntu may lead to system failures or allow execution of unauthorized commands via specially designed input. Follow the update guidelines for resolution.. Axis Security, Ubuntu Update Instructions, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.