Bug 1441538 (CVE-2017-7957)
Summary: | CVE-2017-7957 XStream: DoS when unmarshalling void type | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abhgupta, aileenc, alazarot, bcourt, bdawidow, bkearney, bmcclain, cbillett, chazlett, dblechte, drieden, eedri, etirelli, gvarsami, hghasemb, java-maint, java-sig-commits, jcoleman, jmatthew, kconner, kseifried, kverlaen, ldimaggi, lpetrovi, lsurette, mbaluch, mgoldboi, michal.skrivanek, mizdebsk, mmccune, msimacek, msrb, mstead, mwinkler, nwallace, ohadlevy, pavelp, pdrozd, rbalakri, Rhev-m-bugs, rrajasek, rwagner, rzhang, srevivo, sthorger, tcunning, tiwillia, tjay, tkirby, tlestach, tsanders, ykaul, ylavi |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
It was found that XStream contains a vulnerability that allows a maliciously crafted file to be parsed successfully which could cause an application crash. The crash occurs if the file that is being fed into XStream input stream contains an instances of the primitive type 'void'. An attacker could use this flaw to create a denial of service on the target system.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-10-16 13:44:00 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1441541, 1441542, 1472040, 1472041, 1481373, 1598330, 1598351 | ||
Bug Blocks: | 1441543, 1497821, 1500546, 1551389 |
Description
Andrej Nemec
2017-04-12 08:12:40 UTC
Created jenkins-xstream tracking bugs for this issue: Affects: fedora-all [bug 1441541] Created xstream tracking bugs for this issue: Affects: fedora-all [bug 1441542] External References: http://x-stream.github.io/CVE-2017-7957.html This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2017:1832 https://access.redhat.com/errata/RHSA-2017:1832 Created xstream tracking bugs for this issue: Affects: fedora-all [bug 1481373] This issue has been addressed in the following products: Red Hat JBoss BRMS Via RHSA-2017:2888 https://access.redhat.com/errata/RHSA-2017:2888 This issue has been addressed in the following products: Red Hat JBoss BPM Suite Via RHSA-2017:2889 https://access.redhat.com/errata/RHSA-2017:2889 Created xstream tracking bugs for this issue: Affects: fedora-all [bug 1598330] |