Ubuntu Security Notice USN-4714-1
Ubuntu Security Notice 4714-1 - Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code execution. A remote attacker could run arbitrary shell commands by manipulating the processed input stream. It was discovered that XStream was vulnerable to server-side forgery attacks. A remote attacker could request data from internal resources that are not publicly available only by manipulating the processed input stream. Various other issues were also addressed.
from Packet Storm https://ift.tt/3t7CZ0U
from Packet Storm https://ift.tt/3t7CZ0U
Comments
Post a Comment