Debian Security Update DSA-4619 libxmlrpc3-java - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,872
Reaction score
74
Credits
-1,257
Guillaume Teissier reported that the XMLRPC client in libxmlrpc3-java, an XML-RPC implementation in Java, does perform deserialization of the server-side exception serialized in the faultCause attribute of XMLRPC error response messages. A malicious XMLRPC server can take advantage of this flaw to execute arbitrary code with the privileges of an application using the Apache XMLRPC client library.

Continue reading...
 


Follow Linux.org

Members online


Top