CVE-2017-7957
גבוהה 7.5
תיאור (מקור, אנגלית)
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-20
מוצרים מושפעים
redhat: fuse; redhat: jboss middleware; xstream: xstream; debian: debian linux
קישורים
- http://x-stream.github.io/CVE-2017-7957.html Vendor Advisory
- http://x-stream.github.io/CVE-2017-7957.html Vendor Advisory
- http://www.debian.org/security/2017/dsa-3841 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/100687 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039499 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1832 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2888 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2889 Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125800 Third Party AdvisoryVDB Entry
- https://www-prd-trops.events.ibm.com/node/715749 Broken LinkPermissions Required