Bug 22569 - jackson-databind new security issues CVE-2017-17485 and CVE-2018-5968
Summary: jackson-databind new security issues CVE-2017-17485 and CVE-2018-5968
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-32-OK MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2018-02-10 22:37 CET by David Walser
Modified: 2018-02-25 00:26 CET (History)
6 users (show)

See Also:
Source RPM: jackson-databind-2.7.6-1.2.mga6.src.rpm
CVE:
Status comment: Patches available from Fedora


Attachments

Description David Walser 2018-02-10 22:37:03 CET
Fedora has issued an advisory on February 7:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WW7SXEPYMKLVPDYOEHSN52CK3P6WMIQG/

Mageia 5 and Mageia 6 are also affected (only Mageia 6 needs to be updated).
David Walser 2018-02-10 22:37:15 CET

Whiteboard: (none) => MGA6TOO
CC: (none) => mageia

David Walser 2018-02-10 22:42:34 CET

Status comment: (none) => Patches available from Fedora

Comment 1 David Walser 2018-02-16 20:55:56 CET
Debian has issued an advisory for this on February 15:
https://www.debian.org/security/2018/dsa-4114
Comment 2 David GEIGER 2018-02-17 13:01:32 CET
Done for Cauldron and also for mga6!
Comment 3 David Walser 2018-02-17 17:04:01 CET
Thanks David!

Advisory:
========================

Updated jackson-databind packages fix security vulnerabilities:

A deserialization flaw was discovered in the jackson-databind which could allow
an unauthenticated user to perform code execution by sending maliciously crafted
input to the readValue method of ObjectMapper (CVE-2017-17485).

A flaw was found in FasterXML jackson-databind which allows unauthenticated
remote code execution due deserialization flaws. This is exploitable via two
different gadgets that bypass a blacklist (CVE-2018-5968).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17485
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5968
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WW7SXEPYMKLVPDYOEHSN52CK3P6WMIQG/
========================

Updated packages in core/updates_testing:
========================
jackson-databind-2.7.6-1.3.mga6
jackson-databind-javadoc-2.7.6-1.3.mga6

from jackson-databind-2.7.6-1.3.mga6.src.rpm

Version: Cauldron => 6
CC: (none) => geiger.david68210
Assignee: geiger.david68210 => qa-bugs
Whiteboard: MGA6TOO => (none)

Comment 4 Herman Viaene 2018-02-22 10:05:43 CET
MGA6-32 on Dell Latitude D600 Mate
No installation issues, clean install, does not seem to break antything.
Based on previous updates bugs 21978 and 21428, this should be eniugh to let go.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA6-32-OK

Comment 5 William Kenney 2018-02-22 21:32:26 CET
In VirtualBox, M6, Mate, 64-bit

Package(s) under test:
jackson-databind jackson-databind-javadoc jackson-core jackson-annotations

default install of jackson-databind jackson-databind-javadoc
jackson-core jackson-annotations

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.2.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.2.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-core
Package jackson-core-2.7.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-annotations
Package jackson-annotations-2.7.6-1.mga6.noarch is already installed

Packages install without error

install jackson-databind & jackson-databind-javadoc from updates_testing

[root@localhost wilcal]# urpmi jackson-databind
Package jackson-databind-2.7.6-1.3.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-databind-javadoc
Package jackson-databind-javadoc-2.7.6-1.3.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-core
Package jackson-core-2.7.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi jackson-annotations
Package jackson-annotations-2.7.6-1.mga6.noarch is already installed

Packages update without errors

CC: (none) => wilcal.int

William Kenney 2018-02-22 21:33:12 CET

Keywords: (none) => validated_update
Whiteboard: MGA6-32-OK => MGA6-32-OK MGA6-64-OK
CC: (none) => sysadmin-bugs

Dave Hodgins 2018-02-24 19:31:24 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 6 Mageia Robot 2018-02-25 00:26:21 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0138.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.