libxstream-java 1.4.15-2 source package in Ubuntu

Changelog

libxstream-java (1.4.15-2) unstable; urgency=high

  * Team upload.
  * Fix CVE-2021-21341 to CVE-2021-21351:
    In XStream there is a vulnerability which may allow a remote attacker to
    load and execute arbitrary code from a remote host only by manipulating the
    processed input stream.

    The type hierarchies for java.io.InputStream, java.nio.channels.Channel,
    javax.activation.DataSource and javax.sql.rowsel.BaseRowSet are now
    blacklisted as well as the individual types
    com.sun.corba.se.impl.activation.ServerTableEntry,
    com.sun.tools.javac.processing.JavacProcessingEnvironment$NameProcessIterator,
    sun.awt.datatransfer.DataTransferer$IndexOrderComparator, and
    sun.swing.SwingLazyValue. Additionally the internal type
    Accessor$GetterSetterReflection of JAXB, the internal types
    MethodGetter$PrivilegedGetter and ServiceFinder$ServiceNameIterator of
    JAX-WS, all inner classes of javafx.collections.ObservableList and an
    internal ClassLoader used in a private BCEL copy are now part of the
    default blacklist and the deserialization of XML containing one of the two
    types will fail. You will have to enable these types by explicit
    configuration, if you need them.

 -- Markus Koschany <email address hidden>  Sat, 03 Apr 2021 19:17:05 +0200

Upload details

Uploaded by:
Debian Java Maintainers
Uploaded to:
Sid
Original maintainer:
Debian Java Maintainers
Architectures:
all
Section:
java
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Impish: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
libxstream-java_1.4.15-2.dsc 2.5 KiB f7c80c5cac9c5d3e75ac3d954af015b4453e49dd0972a9fc78b6bd20dc28bf07
libxstream-java_1.4.15.orig.tar.xz 441.8 KiB f905ff9b5d3b7c25914b263903a295d682b476e33d36af7e04a0bee304ad2040
libxstream-java_1.4.15-2.debian.tar.xz 9.1 KiB 7153677cd945bb416bbd1ef69107fb7d65894e0724826180d2d2af7768e7eb24

Available diffs

No changes file available.

Binary packages built by this source

libxstream-java: No summary available for libxstream-java in ubuntu impish.

No description available for libxstream-java in ubuntu impish.