Bug 21978 - jackson-databind new security issue CVE-2017-15095
Summary: jackson-databind new security issue CVE-2017-15095
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5TOO MGA5-32-OK MGA5-64-OK MGA6-32...
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2017-11-03 22:45 CET by David Walser
Modified: 2017-11-16 08:40 CET (History)
7 users (show)

See Also:
Source RPM: jackson-databind-2.7.6-1.1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-11-03 22:45:05 CET
It has been announced on November 2 that the fix for CVE-2017-7525 (Bug 21428) was incomplete:
http://openwall.com/lists/oss-security/2017/11/02/3
David Walser 2017-11-03 22:45:18 CET

CC: (none) => geiger.david68210
Whiteboard: (none) => MGA6TOO, MGA5TOO

Comment 1 David GEIGER 2017-11-04 04:32:28 CET
Fixed on Cauldron, mga6 and also mga5!
Comment 2 David Walser 2017-11-04 16:46:06 CET
Advisory:
========================

Updated jackson-databind packages fix security vulnerability:

An unsafe deserialization vulnerability was found due to incomplete
blacklisting of the unsafe elements, due to an incomplete fix for
CVE-2017-7525 (CVE-2017-15095).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15095
http://openwall.com/lists/oss-security/2017/11/02/3
https://bugzilla.redhat.com/show_bug.cgi?id=1506612
========================

Updated packages in core/updates_testing:
========================
jackson-databind-2.4.3-4.2.mga5
jackson-databind-2.7.6-1.2.mga6
jackson-databind-javadoc-2.7.6-1.2.mga6

from SRPMS:
jackson-databind-2.4.3-4.2.mga5.src.rpm
jackson-databind-2.7.6-1.2.mga6.src.rpm

CC: (none) => mageia
Assignee: mageia => qa-bugs
Whiteboard: MGA6TOO, MGA5TOO => MGA5TOO
Version: Cauldron => 6

Lewis Smith 2017-11-05 13:39:22 CET

Keywords: (none) => advisory

Comment 3 Len Lawrence 2017-11-05 18:48:01 CET
Mageia 6 on x86_64

This has turned up before, and previously nothing was found which uses jackson-databind which does not lead back to java development frameworks of some kind although docker-client is mentioned.

However, the testing of jackson-dataformat-xml around that time involved a java snippet which listed com.fasterxml.jackson.databind.* in the module requirements (imports).

It might be worth running.

CC: (none) => tarazed25

Comment 4 Herman Viaene 2017-11-08 15:54:32 CET
MGA5-32 on Asus A6000VMXfce
No installation issues.
Previous update on this was bug 21428, which was let go on a clean install.
Doing a search in Bugzilla for jackson-dataformat only turns up this current bug. If Len can shed some more light here, I'm willing to keep this bug open for a while.

CC: (none) => herman.viaene

Comment 5 William Kenney 2017-11-09 18:51:39 CET
In VirtualBox, M6, Plasma, 64-bit

Package(s) under test:
jackson-databind jackson-databind-javadoc

default install of jackson-databind & jackson-databind-javadoc

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.1.mga6.noarch is already installed

Packages install without error

install jackson-databind & jackson-databind-javadoc from updates_testing

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.2.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.2.mga6.noarch is already installed

Packages update without errors

CC: (none) => wilcal.int

William Kenney 2017-11-09 18:51:59 CET

Whiteboard: MGA5TOO => MGA5TOO MGA6-64-OK

Comment 6 William Kenney 2017-11-09 19:02:08 CET
In VirtualBox, M6, Plasma, 32-bit

Package(s) under test:
jackson-databind jackson-databind-javadoc

default install of jackson-databind & jackson-databind-javadoc

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.1.mga6.noarch is already installed

Packages install without error

install jackson-databind & jackson-databind-javadoc from updates_testing

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.2.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.2.mga6.noarch is already installed

Packages update without errors

Whiteboard: MGA5TOO MGA6-64-OK => MGA5TOO MGA6-32-OK MGA6-64-OK

Comment 7 William Kenney 2017-11-09 19:10:29 CET
In VirtualBox, M5.1, KDE, 64-bit

Package(s) under test:
jackson-databind jackson-databind-javadoc

default install of jackson-databind & jackson-databind-javadoc

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.4.3-4.1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.4.3-4.mga5.noarch is already installed

Packages install without error

install jackson-databind & jackson-databind-javadoc from updates_testing

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.4.3-4.2.mga5.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.4.3-4.mga5.noarch is already installed

Packages update without errors

Whiteboard: MGA5TOO MGA6-32-OK MGA6-64-OK => MGA5TOO MGA5-64-OK MGA6-32-OK MGA6-64-OK

Comment 8 William Kenney 2017-11-09 19:19:29 CET
In VirtualBox, M5.1, KDE, 32-bit

Package(s) under test:
jackson-databind jackson-databind-javadoc

default install of jackson-databind & jackson-databind-javadoc

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.4.3-4.1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.4.3-4.mga5.noarch is already installed

Packages install without error

install jackson-databind & jackson-databind-javadoc from updates_testing

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.4.3-4.2.mga5.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.4.3-4.mga5.noarch is already installed

Packages update without errors

Whiteboard: MGA5TOO MGA5-64-OK MGA6-32-OK MGA6-64-OK => MGA5TOO MGA5-32-OK MGA5-64-OK MGA6-32-OK MGA6-64-OK

Comment 9 Dave Hodgins 2017-11-12 11:41:07 CET
Validating the update based on the above comments.

Keywords: (none) => validated_update
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 10 Mageia Robot 2017-11-16 08:40:16 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2017-0408.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.