Commits on Source (3)
-
Markus Koschany authored
jackson-databind (2.8.6-1+deb9u3) stretch-security; urgency=high * Team upload. * Fix CVE-2017-17485 and CVE-2018-5968: Bybass of deserialization blackist to disallow unauthenticated remote code execution. These CVE exist due to an incomplete fix for CVE-2017-7525. (Closes: #888316, #888318) jackson-databind (2.8.6-1+deb9u2) stretch-security; urgency=high * Team upload * CVE-2017-15095: incomplete fixes for CVE-2017-7525
44c0d6a2 -
Markus Koschany authored82aca9eb
-
Markus Koschany authoreda3a6b050
debian/patches/CVE-2017-15095_1.patch
0 → 100644
debian/patches/CVE-2017-15095_2.patch
0 → 100644
debian/patches/CVE-2017-15095_3.patch
0 → 100644
debian/patches/CVE-2017-17485.patch
0 → 100644
debian/patches/CVE-2018-5968.patch
0 → 100644
debian/patches/CVE-2018-7489.patch
0 → 100644