Debian Security Update DSA-4004 jackson-databind - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,788
Reaction score
74
Credits
-1,257
Liao Xinxi discovered that jackson-databind, a Java library used to parse JSON and other data formats, did not properly validate user input before attemtping deserialization. This allowed an attacker to perform code execution by providing maliciously crafted input.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top