[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2015:2522 -- centos 7 apache-commons-collections

ID: oval:org.secpod.oval:def:204267Date: (C)2017-04-04   (M)2024-02-19
Class: PATCHFamily: unix




The Apache Commons Collections library provides new interfaces, implementations, and utilities to extend the features of the Java Collections Framework. It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library. With this update, deserialization of certain classes in the commons-collections library is no longer allowed. Applications that require those classes to be deserialized can use the system property "org.apache.commons.collections.enableUnsafeSerialization" to re-enable their deserialization. Further information about this security flaw may be found at: https://access.redhat.com/solutions/2045023 All users of apache-commons-collections are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. All running applications using the commons-collections library must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed : 1279330 - CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation 6. Package List: Red Hat Enterprise Linux Client Optional : Source: apache-commons-collections-3.2.1-22.el7_2.src.rpm noarch: apache-commons-collections-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-javadoc-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-javadoc-3.2.1-22.el7_2.noarch.rpm Red Hat Enterprise Linux ComputeNode Optional : Source: apache-commons-collections-3.2.1-22.el7_2.src.rpm noarch: apache-commons-collections-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-javadoc-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-javadoc-3.2.1-22.el7_2.noarch.rpm Red Hat Enterprise Linux Server : Source: apache-commons-collections-3.2.1-22.el7_2.src.rpm noarch: apache-commons-collections-3.2.1-22.el7_2.noarch.rpm Red Hat Enterprise Linux Server Optional : Source: apache-commons-collections-3.2.1-22.el7_2.src.rpm noarch: apache-commons-collections-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-javadoc-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-javadoc-3.2.1-22.el7_2.noarch.rpm Red Hat Enterprise Linux Workstation : Source: apache-commons-collections-3.2.1-22.el7_2.src.rpm noarch: apache-commons-collections-3.2.1-22.el7_2.noarch.rpm Red Hat Enterprise Linux Workstation Optional : noarch: apache-commons-collections-javadoc-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-3.2.1-22.el7_2.noarch.rpm apache-commons-collections-testframework-javadoc-3.2.1-22.el7_2.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-7501 https://access.redhat.com/security/updates/classification/#important

Platform:
CentOS 7
Product:
apache-commons-collections
Reference:
CESA-2015:2522
CVE-2015-7501
CVE    1
CVE-2015-7501
CPE    2
cpe:/a:apache:apache-commons-collections
cpe:/o:centos:centos:7

© SecPod Technologies