UBUNTU-CVE-2013-7285
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-7285
Summary:
Details: Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
References: https://ubuntu.com/security/CVE-2013-7285, http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html, http://markmail.org/message/kfqoqdfj5fnup5co?q=list:org.codehaus.xstream.dev&page=3, http://xstream.codehaus.org/security.html, https://fisheye.codehaus.org/changelog/xstream?cs=2210, https://www.cve.org/CVERecord?id=CVE-2013-7285
Affected packages
Package
Name: libxstream-java
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
