Following CVEs were reported against the jackson-databind source package : . Package : jackson-databind Version : 2.4.2-2+deb8u14 CVE ID : CVE-2020-10968 CVE-2020-10969 CVE-2020-11111 CVE-2020-11112 CVE-2020-11113 CVE-2020-11619 CVE-2020-11620 Following CVEs were reported against the jackson-databind source package : CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). CVE-2020-11619 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). CVE-2020-11620 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). For Debian 8 "Jessie",these problems have been fixed in version 2.4.2-2+deb8u14. We recommend that you upgrade your jackson-databind packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Best, Utkarsh . Ensure your jackson-databind library is updated to address significant serialization vulnerabilities linked to recent CVEs identified.. jackson-databind security, debian LTS, software vulnerabilities, package updates, serialization threats. . Severity: Critical. LinuxSecurity.com Team
krb5: null dereference in kadmind or DN container check bypass by supplying special crafted data (CVE-2018-5729) * krb5: DN container check bypass by supplying special crafted data (CVE-2018-5730) SL7 x86_64 krb5-debuginfo-1.15.1-34.el7.i686.rpm krb5-debuginfo-1.15.1-34.el7.x86_64.rpm krb5-libs-1.15.1-34.el7.i686.rpm krb5-libs-1.15.1-34.el7.x86_64.rpm krb5-pkinit-1.15.1 [More...]. Synopsis: Low: krb5 security, bug fix, and enhancement update Advisory ID: SLSA-2018:3071-1 Issue Date: 2018-10-30 CVE Numbers: CVE-2018-5730 CVE-2018-5729 -- Security Fix(es): * krb5: null dereference in kadmind or DN container check bypass by supplying special crafted data (CVE-2018-5729) * krb5: DN container check bypass by supplying special crafted data (CVE-2018-5730) -- SL7 x86_64 krb5-debuginfo-1.15.1-34.el7.i686.rpm krb5-debuginfo-1.15.1-34.el7.x86_64.rpm krb5-libs-1.15.1-34.el7.i686.rpm krb5-libs-1.15.1-34.el7.x86_64.rpm krb5-pkinit-1.15.1-34.el7.x86_64.rpm krb5-workstation-1.15.1-34.el7.x86_64.rpm libkadm5-1.15.1-34.el7.i686.rpm libkadm5-1.15.1-34.el7.x86_64.rpm krb5-devel-1.15.1-34.el7.i686.rpm krb5-devel-1.15.1-34.el7.x86_64.rpm krb5-server-1.15.1-34.el7.x86_64.rpm krb5-server-ldap-1.15.1-34.el7.x86_64.rpm - Scientific Linux Development Team . Minor security advisory for krb5 patches on Scientific Linux resolving null pointer dereference and potential bypass vulnerabilities.. krb5 Update, Scientific Linux, kadmin Issues, Low Severity Advisory. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.