[ GLSA 202107-37 ] Apache Commons Collections: Remote code execution

John Helmert III <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <[email protected]>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202107-37
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: Apache Commons Collections: Remote code execution
     Date: July 16, 2021
     Bugs: #739348
       ID: 202107-37

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Apache Commons Collections unsafely deserializes untrusted input,
potentially resulting in arbitrary code execution.

Background
==========

Apache Commons Collections extends the JCF classes with new interfaces,
implementations and utilities.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-java/commons-collections
                                  < 3.2.2                    >= 3.2.2 

Description
===========

Some classes in the Apache Commons Collections functor package
deserialized potentially untrusted input by default.

Impact
======

Deserializing untrusted input using Apache Commons Collections could
result in remote code execution.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Apache Commons Collections users should upgrade to the latest
version:

  # emerge --sync
  # emerge --ask --oneshot -v ">=dev-java/commons-collections-3.2.2"

References
==========

[ 1 ] CVE-2017-15708
      https://nvd.nist.gov/vuln/detail/CVE-2017-15708

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202107-37

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmDxB6YACgkQXP0dAeB+
IziQfQ//X74ypBJRB2FG1E/pf4wsNqJwBnCEqCGwim0PKY+vszlpuugOiRixeFh5
J78A2zrCA6KWXIRhSmYECgfcKayon4ao8JT9jxX6QsW4vpcPw3RwZkKG9c9lQ4aE
oNeI7EYJxRBksOGN2mY/hu0YvaUwMkM+Ar46s6LnsEBX6McKnAmk5db9hTyksZXf
i50RemrvFKwkkGaIsqHCYPW8SWcbq4IEv0H67xrS9AqQO6Y3WftGTrUmcbVDJNSg
BltUPDwluV29IBWs8JvoKDyUIlNIZ03kfCGfc8FVBLLKEXOqNl594yKohzm1Tf/W
qXho3hcMsxQ0BGtT2OUacHommpnymDPgj2s9kRiJez3GAr4WYbFv9S+4SaUxV5t9
Zb0XUQPtDm1HdOnXsIolLzdd9dEjfAJXFHTf29O+0vjFNeB7ql9kCB/yUSyIoFc6
JS2RFCrgwrnvkLfMjQtG1rdJpnYn0UdeS/1WLMCJbNtPyy9nNeTjeV5/t0PRn0Rt
kY+Imn8DpLi0p7VzZhNB/2KRNRcmYioZZAxf98oVJeqw5bHFjy937f2L1TFnC9nG
10lnE7aIlaQsP3r3+IfKNQUAsu/sTtmvxZNjVm4jw85igIZHFotKlwRsKLTv82I7
a6pctolREkgfU30GCnR6F5F9vCmRhSnz26NxPOU3xmOiTUKF2XI=
=aE2I
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.