VDB
MAGEIA-2016-164
MAGEIA-2016-164
PUBLISHED
Updated xstream packages fix security vulnerability: XStream (x-stream.github.io) is a Java library to marshal Java objects into XML and back. For this purpose it supports a lot of different XML parsers. Some of those can also process external entities which was enabled by default. An attacker could therefore provide manipulated XML as input to access data on the file system (CVE-2016-3674).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | xstream | 0, 1.4.9-1.mga5 |
| Mageia | javapackages-tools | 0, 4.1.0-15.1.mga5 |
Timeline
- May 5, 2016 CVE Updated
- May 5, 2016 CVE Published