MGASA-2016-0164
Dashboard / Vulnerabilities / MGASA-2016-0164
Summary: Updated xstream packages fix CVE-2016-3674
Details: Updated xstream packages fix security vulnerability: XStream (x-stream.github.io) is a Java library to marshal Java objects into XML and back. For this purpose it supports a lot of different XML parsers. Some of those can also process external entities which was enabled by default. An attacker could therefore provide manipulated XML as input to access data on the file system (CVE-2016-3674).
References: https://advisories.mageia.org/MGASA-2016-0164.html, https://bugs.mageia.org/show_bug.cgi?id=18277, https://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html
Affected packages
Package
Name: xstream
Purl: pkg:rpm/mageia/xstream?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
