Re: CVE-2016-4000

Adam Burke <[email protected]> Fri, 21 Jun 2019 21:26:21 +1000
Newsgroups gmane.comp.lang.jython.user
Message-ID <[email protected]>
--===============2946774113045620929==
Content-Type: multipart/alternative;
	boundary=Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC
Content-Transfer-Encoding: 7bit


--Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Going from the bug report, I didn=E2=80=99t work on it, and a core dev could=
 correct me, but it=E2=80=99s specifically about deserializing Python object=
s.

https://hg.python.org/jython/rev/d06e29d100c0

It would depend on whether your app had an exposed endpoint that accepted Py=
thon objects. All the usual caveats about eg web form data hygiene apply.

Without knowing your exact organizational or technical constraint, I would m=
ention that security bugs can be excellent sticks for pushing through needed=
, but delayed, upgrades to current versions of infrastructure and libraries,=
 like upgrading to Jython 2.7.1. Priorities can suddenly realign.

Cheers
Adam

> =E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5=EF=BC=8C=E4=B8=8B=E5=8D=889:1=
9=EF=BC=8CAdam Burke <[email protected]> =E5=86=99=E9=81=93=EF=BC=9A
>=20
> Going from the bug report, it=E2=80=99s specifically about deserializing P=
ython objects.
>=20
> https://hg.python.org/jython/rev/d06e29d100c0
>=20
> It would depend on whether your app had an exposed endpoint that accepted P=
ython objects. All the usual caveats about eg web form data hygiene apply.
>=20
> Without knowing your exact organizational or technical constraint, I would=
 say that security bugs can be excellent sticks for pushing through needed, b=
ut delayed, upgrades to current versions of infrastructure and libraries, li=
ke upgrading to Jython 2.7.1. Priorities can suddenly realign.
>=20
> Cheers
> Adam
>=20
>> =E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5=EF=BC=8C=E4=B8=8B=E5=8D=888:=
57=EF=BC=8CSamuel Schober <[email protected]> =E5=86=99=E9=81=93=EF=BC=9A
>>=20
>> Hello,
>>=20
>> =20
>>=20
>> I am using the jython package for an project and have a question about an=
 issue you had.
>>=20
>> =20
>>=20
>> The used version is 2.5.3 and unfortunally it can not be updated to 2.7.1=
. Now I found the following issue:=20
>>=20
>> http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-4000
>>=20
>> =20
>>=20
>> It notices that jython allows attackers to execute arbitrary code and I w=
anted to ask what kind of code could be executed?
>>=20
>> Is it only python code which could be executed or is it possible to execu=
te any kind of binary code?
>>=20
>> And is it possible to have influence on the server outside of the applica=
tion or does it just affect my application?
>>=20
>> =20
>>=20
>> I hope you can help me with that question.
>>=20
>> =20
>>=20
>> Best regards,
>>=20
>> Samuel Schober
>>=20
>> _______________________________________________
>> Jython-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/jython-users

--Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><span style=3D"background-color: rgba(255, 2=
55, 255, 0);">Going from the bug report, I didn=E2=80=99t work on it, and a c=
ore dev could correct me, but it=E2=80=99s specifically about deserializing P=
ython objects.</span><div><span style=3D"background-color: rgba(255, 255, 25=
5, 0);"><br></span></div><div><a href=3D"https://hg.python.org/jython/rev/d0=
6e29d100c0" style=3D"caret-color: rgb(0, 0, 0); background-color: rgba(255, 2=
55, 255, 0);"><font color=3D"#000000">https://hg.python.org/jython/rev/d06e2=
9d100c0</font></a></div><div><span style=3D"background-color: rgba(255, 255,=
 255, 0);"><br></span></div><div><span style=3D"background-color: rgba(255, 2=
55, 255, 0);">It would depend on whether your app had an exposed endpoint th=
at accepted Python objects. All the usual caveats about eg web form data hyg=
iene apply.</span></div><div><span style=3D"background-color: rgba(255, 255,=
 255, 0);"><br></span></div><div><span style=3D"background-color: rgba(255, 2=
55, 255, 0);">Without knowing your exact organizational or technical constra=
int, I would mention</span><span style=3D"background-color: rgba(255, 255, 2=
55, 0);">&nbsp;that security bugs can be excellent sticks for pushing throug=
h needed, but delayed, upgrades to current versions of infrastructure and li=
braries, like upgrading to Jython 2.7.1. Priorities can suddenly realign.</s=
pan></div><div><br></div>Cheers<br><div id=3D"AppleMailSignature" dir=3D"ltr=
">Adam</div><div dir=3D"ltr"><br>=E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=A5=
=EF=BC=8C=E4=B8=8B=E5=8D=889:19=EF=BC=8CAdam Burke &lt;<a href=3D"mailto:ada=
[email protected]">[email protected]</a>&gt; =E5=86=99=E9=81=93=EF=BC=
=9A<br><br></div><blockquote type=3D"cite"><div dir=3D"ltr"><meta http-equiv=
=3D"content-type" content=3D"text/html; charset=3Dutf-8">Going from the bug r=
eport, it=E2=80=99s specifically about deserializing Python objects.<div><br=
></div><div><a href=3D"https://hg.python.org/jython/rev/d06e29d100c0">https:=
//hg.python.org/jython/rev/d06e29d100c0</a></div><div><br></div><div>It woul=
d depend on whether your app had an exposed endpoint that accepted Python ob=
jects. All the usual caveats about eg web form data hygiene apply.</div><div=
><br></div><div>Without knowing your exact organizational or technical const=
raint, I would say that security bugs can be excellent sticks for pushing th=
rough needed, but delayed, upgrades to current versions of infrastructure an=
d libraries, like upgrading to Jython 2.7.1. Priorities can suddenly realign=
.</div><div><br></div><div>Cheers<br><div id=3D"AppleMailSignature" dir=3D"l=
tr">Adam</div><div dir=3D"ltr"><br>=E5=9C=A8 2019=E5=B9=B46=E6=9C=8821=E6=97=
=A5=EF=BC=8C=E4=B8=8B=E5=8D=888:57=EF=BC=8CSamuel Schober &lt;<a href=3D"mai=
lto:[email protected]">[email protected]</a>&gt; =E5=86=99=E9=81=93=EF=BC=
=9A<br><br></div><blockquote type=3D"cite"><div dir=3D"ltr"><div style=3D"fo=
nt-family: Verdana;font-size: 12.0px;"><div>
<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">Hello,</span></span></p>

<p>&nbsp;</p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">I am using the jython package for an project and have a question about a=
n issue you had.</span></span></p>

<p>&nbsp;</p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">The used version is 2.5.3 and unfortunally it can not be updated to 2.7=
.1. Now I found the following issue:&nbsp;</span></span></p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif"><a href=3D"http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-400=
0" style=3D"color:#0563c1; text-decoration:underline">http://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2016-4000</a></span></span></p>

<p>&nbsp;</p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">It notices that jython allows attackers to execute arbitrary code and I=
 wanted to ask what kind of code could be executed?</span></span></p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">Is it only python code which could be executed or is it possible to exe=
cute any kind of binary code? </span></span></p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">And is it possible&nbsp;to have influence on the server outside of the a=
pplication or does it just affect my application?</span></span></p>

<p>&nbsp;</p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">I hope you can help me with that question.</span></span></p>

<p>&nbsp;</p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">Best regards,</span></span></p>

<p><span style=3D"font-size:11pt"><span style=3D"font-family:Calibri,sans-se=
rif">Samuel Schober</span></span></p>
</div></div>

</div></blockquote><blockquote type=3D"cite"><div dir=3D"ltr"></div></blockq=
uote><blockquote type=3D"cite"><div dir=3D"ltr"><span>______________________=
_________________________</span><br><span>Jython-users mailing list</span><b=
r><span><a href=3D"mailto:[email protected]">Jython-users@l=
ists.sourceforge.net</a></span><br><span><a href=3D"https://lists.sourceforg=
e.net/lists/listinfo/jython-users">https://lists.sourceforge.net/lists/listi=
nfo/jython-users</a></span><br></div></blockquote></div></div></blockquote><=
/body></html>=

--Apple-Mail-8009D47D-F328-41FE-BBC4-316E079323CC--


--===============2946774113045620929==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2946774113045620929==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Jython-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/jython-users

--===============2946774113045620929==--