Re: CVE-2016-4000
Adam Burke <[email protected]> Fri, 21 Jun 2019 21:26:21 +1000
| Newsgroups | gmane.comp.lang.jython.user |
|---|---|
| Message-ID | <[email protected]> |
--===============2946774113045620929== Content-Type: multipart/alternative; boundary=Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC Content-Transfer-Encoding: 7bit --Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Going from the bug report, I didn=E2=80=99t work on it, and a core dev could= correct me, but it=E2=80=99s specifically about deserializing Python object= s. https://hg.python.org/jython/rev/d06e29d100c0 It would depend on whether your app had an exposed endpoint that accepted Py= thon objects. All the usual caveats about eg web form data hygiene apply. Without knowing your exact organizational or technical constraint, I would m= ention that security bugs can be excellent sticks for pushing through needed= , but delayed, upgrades to current versions of infrastructure and libraries,= like upgrading to Jython 2.7.1. Priorities can suddenly realign. Cheers Adam > =E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5=EF=BC=8C=E4=B8=8B=E5=8D=889:1= 9=EF=BC=8CAdam Burke <[email protected]> =E5=86=99=E9=81=93=EF=BC=9A >=20 > Going from the bug report, it=E2=80=99s specifically about deserializing P= ython objects. >=20 > https://hg.python.org/jython/rev/d06e29d100c0 >=20 > It would depend on whether your app had an exposed endpoint that accepted P= ython objects. All the usual caveats about eg web form data hygiene apply. >=20 > Without knowing your exact organizational or technical constraint, I would= say that security bugs can be excellent sticks for pushing through needed, b= ut delayed, upgrades to current versions of infrastructure and libraries, li= ke upgrading to Jython 2.7.1. Priorities can suddenly realign. >=20 > Cheers > Adam >=20 >> =E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5=EF=BC=8C=E4=B8=8B=E5=8D=888:= 57=EF=BC=8CSamuel Schober <[email protected]> =E5=86=99=E9=81=93=EF=BC=9A >>=20 >> Hello, >>=20 >> =20 >>=20 >> I am using the jython package for an project and have a question about an= issue you had. >>=20 >> =20 >>=20 >> The used version is 2.5.3 and unfortunally it can not be updated to 2.7.1= . Now I found the following issue:=20 >>=20 >> http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-4000 >>=20 >> =20 >>=20 >> It notices that jython allows attackers to execute arbitrary code and I w= anted to ask what kind of code could be executed? >>=20 >> Is it only python code which could be executed or is it possible to execu= te any kind of binary code? >>=20 >> And is it possible to have influence on the server outside of the applica= tion or does it just affect my application? >>=20 >> =20 >>=20 >> I hope you can help me with that question. >>=20 >> =20 >>=20 >> Best regards, >>=20 >> Samuel Schober >>=20 >> _______________________________________________ >> Jython-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/jython-users --Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><span style=3D"background-color: rgba(255, 2= 55, 255, 0);">Going from the bug report, I didn=E2=80=99t work on it, and a c= ore dev could correct me, but it=E2=80=99s specifically about deserializing P= ython objects.</span><div><span style=3D"background-color: rgba(255, 255, 25= 5, 0);"><br></span></div><div><a href=3D"https://hg.python.org/jython/rev/d0= 6e29d100c0" style=3D"caret-color: rgb(0, 0, 0); background-color: rgba(255, 2= 55, 255, 0);"><font color=3D"#000000">https://hg.python.org/jython/rev/d06e2= 9d100c0</font></a></div><div><span style=3D"background-color: rgba(255, 255,= 255, 0);"><br></span></div><div><span style=3D"background-color: rgba(255, 2= 55, 255, 0);">It would depend on whether your app had an exposed endpoint th= at accepted Python objects. All the usual caveats about eg web form data hyg= iene apply.</span></div><div><span style=3D"background-color: rgba(255, 255,= 255, 0);"><br></span></div><div><span style=3D"background-color: rgba(255, 2= 55, 255, 0);">Without knowing your exact organizational or technical constra= int, I would mention</span><span style=3D"background-color: rgba(255, 255, 2= 55, 0);"> that security bugs can be excellent sticks for pushing throug= h needed, but delayed, upgrades to current versions of infrastructure and li= braries, like upgrading to Jython 2.7.1. Priorities can suddenly realign.</s= pan></div><div><br></div>Cheers<br><div id=3D"AppleMailSignature" dir=3D"ltr= ">Adam</div><div dir=3D"ltr"><br>=E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5= =EF=BC=8C=E4=B8=8B=E5=8D=889:19=EF=BC=8CAdam Burke <<a href=3D"mailto:ada= [email protected]">[email protected]</a>> =E5=86=99=E9=81=93=EF=BC= =9A<br><br></div><blockquote type=3D"cite"><div dir=3D"ltr"><meta http-equiv= =3D"content-type" content=3D"text/html; charset=3Dutf-8">Going from the bug r= eport, it=E2=80=99s specifically about deserializing Python objects.<div><br= ></div><div><a href=3D"https://hg.python.org/jython/rev/d06e29d100c0">https:= //hg.python.org/jython/rev/d06e29d100c0</a></div><div><br></div><div>It woul= d depend on whether your app had an exposed endpoint that accepted Python ob= jects. All the usual caveats about eg web form data hygiene apply.</div><div= ><br></div><div>Without knowing your exact organizational or technical const= raint, I would say that security bugs can be excellent sticks for pushing th= rough needed, but delayed, upgrades to current versions of infrastructure an= d libraries, like upgrading to Jython 2.7.1. Priorities can suddenly realign= .</div><div><br></div><div>Cheers<br><div id=3D"AppleMailSignature" dir=3D"l= tr">Adam</div><div dir=3D"ltr"><br>=E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97= =A5=EF=BC=8C=E4=B8=8B=E5=8D=888:57=EF=BC=8CSamuel Schober <<a href=3D"mai= lto:[email protected]">[email protected]</a>> =E5=86=99=E9=81=93=EF=BC= =9A<br><br></div><blockquote type=3D"cite"><div dir=3D"ltr"><div style=3D"fo= nt-family: Verdana;font-size: 12.0px;"><div> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">Hello,</span></span></p> <p> </p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">I am using the jython package for an project and have a question about a= n issue you had.</span></span></p> <p> </p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">The used version is 2.5.3 and unfortunally it can not be updated to 2.7= .1. Now I found the following issue: </span></span></p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif"><a href=3D"http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-400= 0" style=3D"color:#0563c1; text-decoration:underline">http://cve.mitre.org/c= gi-bin/cvename.cgi?name=3DCVE-2016-4000</a></span></span></p> <p> </p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">It notices that jython allows attackers to execute arbitrary code and I= wanted to ask what kind of code could be executed?</span></span></p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">Is it only python code which could be executed or is it possible to exe= cute any kind of binary code? </span></span></p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">And is it possible to have influence on the server outside of the a= pplication or does it just affect my application?</span></span></p> <p> </p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">I hope you can help me with that question.</span></span></p> <p> </p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">Best regards,</span></span></p> <p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se= rif">Samuel Schober</span></span></p> </div></div> </div></blockquote><blockquote type=3D"cite"><div dir=3D"ltr"></div></blockq= uote><blockquote type=3D"cite"><div dir=3D"ltr"><span>______________________= _________________________</span><br><span>Jython-users mailing list</span><b= r><span><a href=3D"mailto:[email protected]">Jython-users@l= ists.sourceforge.net</a></span><br><span><a href=3D"https://lists.sourceforg= e.net/lists/listinfo/jython-users">https://lists.sourceforge.net/lists/listi= nfo/jython-users</a></span><br></div></blockquote></div></div></blockquote><= /body></html>= --Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC-- --===============2946774113045620929== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2946774113045620929== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Jython-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/jython-users --===============2946774113045620929==--