VDB

MAGEIA-2016-164

MAGEIA-2016-164 PUBLISHED

Updated xstream packages fix security vulnerability: XStream (x-stream.github.io) is a Java library to marshal Java objects into XML and back. For this purpose it supports a lot of different XML parsers. Some of those can also process external entities which was enabled by default. An attacker could therefore provide manipulated XML as input to access data on the file system (CVE-2016-3674).

Affected Products

VendorProductVersions
Mageiaxstream0, 1.4.9-1.mga5
Mageiajavapackages-tools0, 4.1.0-15.1.mga5

Timeline

  • May 5, 2016 CVE Updated
  • May 5, 2016 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›