Date: Sun, 8 Nov 2015 19:36:20 -0500 (EST) From: Jason Shepherd <jshepher@...hat.com> To: oss-security@...ts.openwall.com Subject: Assign CVE for common-collections remote code execution on deserialisation flaw Hello oss-esc, It was found that a flaw in Apache commons-collections Java library allowed remote code execution when Deserialised with Java Object Serialization. Full details of the vulnerability can be found in this recent blog post, . A proposed patch for 3.2.x branch has been submitted upstream, but no release has been made with the fix at the current time. The issue affects version 3.x, and 4.x of Apache common-collections, .  http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/  https://issues.apache.org/jira/browse/COLLECTIONS-580 Regards, Jason Shepherd Red Hat Product Security
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ