Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.maint.java > #8905
| From | Stian Soiland-Reyes <stain@apache.org> |
|---|---|
| Newsgroups | linux.debian.maint.java |
| Subject | Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) |
| Date | 2016-02-29 13:10 +0100 |
| Message-ID | <r7uOf-2PD-23@gated-at.bofh.it> (permalink) |
| References | <r3Scq-4Z3-7@gated-at.bofh.it> <r6r62-44C-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Yes, that looks like it should be sufficient to fix the exploit both for java.util deserialization and xmlbeans deserialization. On 26 February 2016 at 13:51, Markus Koschany <apo@debian.org> wrote: > Am 19.02.2016 um 13:10 schrieb Stian Soiland-Reyes: >> Hi, >> >> BeanShell aka bsh has released a security fix 2.0b6: >> >> https://github.com/beanshell/beanshell/releases/tag/2.0b6 >> >> It has been reported to MITRE as CVE-2016-2510. > > Hi Stian, > > I intend to backport your changes to fix CVE-2016-2510. Looking at the > relevant commits, I could condense the changes to create the attached > patch. Could you take a look at it and confirm that this is sufficient? > > Regards, > > Markus > -- Stian Soiland-Reyes Apache Taverna (incubating), Apache Commons RDF (incubating) http://orcid.org/0000-0001-9842-9718
Back to linux.debian.maint.java | Previous | Next — Previous in thread | Next in thread | Find similar
bsh (BeanShell) security vulnerability (CVE-2016-2510) Stian Soiland-Reyes <stain@apache.org> - 2016-02-19 13:20 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Emmanuel Bourg <ebourg@apache.org> - 2016-02-19 14:40 +0100
Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510) Stian Soiland-Reyes <stain@apache.org> - 2016-02-19 17:30 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Markus Koschany <apo@debian.org> - 2016-02-26 15:00 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Stian Soiland-Reyes <stain@apache.org> - 2016-02-29 13:10 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Sébastien Delafond <seb@debian.org> - 2016-03-01 14:20 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Markus Koschany <apo@debian.org> - 2016-03-01 16:10 +0100
Re: bsh (BeanShell) security vulnerability (CVE-2016-2510) Sébastien Delafond <seb@debian.org> - 2016-03-01 17:10 +0100
csiph-web