MGASA-2016-0012
Dashboard / Vulnerabilities / MGASA-2016-0012
Summary: Updated apache-commons-collections packages fix security vulnerability
Details: It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library (CVE-2015-7501). With this update, deserialization of certain classes in the commons-collections library is no longer allowed. Applications that require those classes to be deserialized can use the system property "org.apache.commons.collections.enableUnsafeSerialization" to re-enable their deserialization.
References: https://advisories.mageia.org/MGASA-2016-0012.html, https://bugs.mageia.org/show_bug.cgi?id=17227, https://blogs.apache.org/foundation/entry/apache_commons_statement_to_widespread, https://rhn.redhat.com/errata/RHSA-2015-2522.html
Affected packages
Package
Name: apache-commons-collections
Purl: pkg:rpm/mageia/apache-commons-collections?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
