Commits on Source (2)
-
jackson-databind (2.4.2-2+deb8u8) jessie-security; urgency=high * Non-maintainer upload by the LTS team. * Fix CVE-2019-14379, CVE-2019-14439: Deserialization flaws were discovered in jackson-databind relating to EHCache and logback/jndi, which could allow an unauthenticated user to perform remote code execution. The issue was resolved by extending the blacklist and blocking more classes from polymorphic deserialization. (Closes: #933393)
-
Markus Koschany authored
jackson-databind (2.4.2-2+deb8u9) jessie-security; urgency=high * Non-maintainer upload by the LTS team. * Fix CVE-2019-14540, CVE-2019-16335, CVE-2019-16942 and CVE-2019-16943. Deserialization flaws were discovered in jackson-databind relating to com.zaxxer.hikari.HikariConfig, com.zaxxer.hikari.HikariDataSource, commons-dbcp and com.p6spy.engine.spy.P6DataSource, which could allow an unauthenticated user to perform remote code execution. The issue was resolved by extending the blacklist and blocking more classes from polymorphic deserialization.
debian/patches/CVE-2019-14540.patch
0 → 100644
debian/patches/CVE-2019-16335.patch
0 → 100644