Commits on Source 3

  • Markus Koschany's avatar
    Import Debian changes 2.8.6-1+deb9u5 · c5b13dc7
    Markus Koschany authored
    jackson-databind (2.8.6-1+deb9u5) stretch-security; urgency=high
    
      * Team upload.
      * Fix CVE-2018-11307, CVE-2018-12022, CVE-2018-12023, CVE-2018-14718,
        CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360,
        CVE-2018-19361 and CVE-2018-19362.
        Several deserialization flaws were discovered in jackson-databind which
        could allow an unauthenticated user to perform code execution. The issue
        was resolved by extending the blacklist and blocking more classes from
        polymorphic deserialization.
    c5b13dc7
  • Markus Koschany's avatar
    Add CVE-2019-12086.patch · 6733e2fb
    Markus Koschany authored
    6733e2fb
  • Markus Koschany's avatar
    Update changelog · 5fe2d6ac
    Markus Koschany authored
    5fe2d6ac
Loading
Loading