Debian Security Update DSA-4037 jackson-databind - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,789
Reaction score
74
Credits
-1,257
It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing: following DSA-4004-1 for CVE-2017-7525, an additional set of classes was identified as unsafe for deserialization.

Continue reading...
 
Top