[CVEs] Creates executables class files with wrong permissions, Unsafe deserialization leads to code execution
Bug #1714728 reported by
Simon Quigley
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
jython (Ubuntu) |
Fix Released
|
Medium
|
Simon Quigley | ||
Trusty |
Fix Released
|
High
|
Simon Quigley | ||
Xenial |
Fix Released
|
High
|
Simon Quigley | ||
Zesty |
Fix Released
|
High
|
Simon Quigley | ||
Artful |
Fix Released
|
Medium
|
Simon Quigley |
Bug Description
This aims to fix two CVEs:
- CVE-2013-2027: Creates executables class files with wrong permissions
- CVE-2016-4000: Unsafe deserialization leads to code execution
While CVE-2013-2027 is not shown as fixed in Debian and Red Hat, it is fixed in OpenSUSE (openSUSE-
CVE-2016-4000 was fixed in Debian in 2.5.3-17, and that's in Artful, but we still need fixes for Trusty, Xenial, and Zesty.
Changed in jython (Ubuntu Artful): | |
status: | In Progress → Fix Committed |
To post a comment you must log in.
Since CVE-2016-4000 is High priority, marking as High priority in all releases affected, marking as Medium in Artful.