MGASA-2019-0079
Dashboard / Vulnerabilities / MGASA-2019-0079
Summary: Updated logback packages fix security vulnerability
Details: It was found that logback is vulnerable to a deserialization issue. Logback can be configured to allow remote logging through SocketServer/ServerSocketReceiver interfaces that can accept untrusted serialized data. Authenticated attackers on the adjacent network can leverage this vulnerability to execute arbitrary code through deserialization of custom gadget chains (CVE-2017-5929).
References: https://advisories.mageia.org/MGASA-2019-0079.html, https://bugs.mageia.org/show_bug.cgi?id=23721, https://bugzilla.redhat.com/show_bug.cgi?id=1432858
Affected packages
Package
Name: logback
Purl: pkg:rpm/mageia/logback?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
