VDB
MAGEIA-2019-79
MAGEIA-2019-79
PUBLISHED
It was found that logback is vulnerable to a deserialization issue. Logback can be configured to allow remote logging through SocketServer/ServerSocketReceiver interfaces that can accept untrusted serialized data. Authenticated attackers on the adjacent network can leverage this vulnerability to execute arbitrary code through deserialization of custom gadget chains (CVE-2017-5929).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | logback | 1.1.3-2.1.mga6, 0, 1.1.3-2.1.mga6 |
| Mageia | python-voevent-parse | 0, 1.0.1-2.1.mga6 |
Timeline
- Feb 14, 2019 CVE Updated
- Feb 14, 2019 CVE Published
References
- Updated logback packages fix security vulnerability advisory
- Updated logback packages fix security vulnerability issue
- Updated logback packages fix security vulnerability issue
- Updated python-voevent-parse packages fix install issues advisory
- Updated python-voevent-parse packages fix install issues issue