Date: Thu, 2 Nov 2017 11:51:59 +1030 From: Doran Moppert <dmoppert@...hat.com> To: oss-security@...ts.openwall.com Subject: CVE-2017-15095: further deserialisation attacks against jackson-databind (follow-up to CVE-2017-7525) In July, deserialisation vulnerabilities were disclosed affecting jackson-databind , assigned CVE-2017-7525. These were patched upstream by blacklisting vulnerable classes, resulting in release 2.8.9 and the issue was closed. Various downstreams including Red Hat issued a fix at this point. 1: https://github.com/FasterXML/jackson-databind/issues/1599 But blacklists being what they are, a further set of dangerous classes have been added since (all included in release 2.9.1). The further patches reference the original ticket, but given that security releases have already been issued for CVE-2017-7525 based on 2.8.9, we thought it prudent to issue a new CVE ID covering the additional classes: CVE-2017-15095. This issue and CVE-2017-7525 were reported by Liao Xinxi of NSFOCUS. Note that there is a mitigation addressing both of these CVEs described at https://bugzilla.redhat.com/show_bug.cgi?id=1462702#c12 More detail below from : 2: https://bugzilla.redhat.com/show_bug.cgi?id=1506612#c3 > Other distributions may have made the same mistake, since the original > upstream ticket was closed before additional names were added to the > blacklist. > > Original ticket + patches (CVE-2017-7525): > > https://github.com/FasterXML/jackson-databind/issues/1599 > https://github.com/FasterXML/jackson-databind/commit/60d459ce > https://github.com/FasterXML/jackson-databind/commit/3bfbb835 > > Further tickets and patches to block more dangerous types (I think > these are > all): > > https://github.com/FasterXML/jackson-databind/issues/1680 > https://github.com/FasterXML/jackson-databind/issues/1723 > https://github.com/FasterXML/jackson-databind/issues/1737 > > https://github.com/FasterXML/jackson-databind/commit/e8f043d1 > https://github.com/FasterXML/jackson-databind/commit/ddfddfba > > This CVE-2017-15095 should be considered to include everything in > NO_DESER_CLASS_NAMES as of today: > > > https://github.com/FasterXML/jackson-databind/blob/ > 7093008aa2afe8068e120df850189ae072dfa1b2/src/main/java/com/fasterxml/ > jackson/databind/deser/BeanDeserializerFactory.java#L43 -- Doran Moppert Red Hat Product Security Content of type "application/pgp-signature" skipped
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ