概述
Important: xstream security update
类型/严重性
Security Advisory: Important
标题
An update for xstream is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
描述
XStream is a Java XML serialization library to serialize objects to and deserialize object from XML.
Security Fix(es):
- XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet (CVE-2021-21344)
- XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry (CVE-2021-21345)
- XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue (CVE-2021-21346)
- XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator (CVE-2021-21347)
- XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader (CVE-2021-21350)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
受影响的产品
-
Red Hat Enterprise Linux Server 7 x86_64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
-
Red Hat Enterprise Linux Workstation 7 x86_64
-
Red Hat Enterprise Linux Desktop 7 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 7 s390x
-
Red Hat Enterprise Linux for Power, big endian 7 ppc64
-
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
-
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
修复
-
BZ - 1942554
- CVE-2021-21344 XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet
-
BZ - 1942558
- CVE-2021-21345 XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry
-
BZ - 1942578
- CVE-2021-21346 XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue
-
BZ - 1942629
- CVE-2021-21347 XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator
-
BZ - 1942637
- CVE-2021-21350 XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader
备注:
可能有这些软件包的更新版本。
点击软件包名称查看详情。
Red Hat Enterprise Linux Server 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| x86_64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| x86_64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Workstation 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| x86_64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Desktop 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| x86_64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux for IBM z Systems 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| s390x |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux for Power, big endian 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| ppc64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux for Scientific Computing 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| x86_64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux for Power, little endian 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| ppc64le |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| s390x |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| ppc64 |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
| SRPM |
|
xstream-1.3.1-13.el7_9.src.rpm
|
SHA-256: 8bbba051178f7c7034683260f7910d1f7b408afae1983d10e0ba6f202b369255 |
| ppc64le |
|
xstream-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: 6fd18baf21cbc767e4524e286a861097d3fced3322527b10aef8413ff671f7f9 |
|
xstream-javadoc-1.3.1-13.el7_9.noarch.rpm
|
SHA-256: e0b2c7fa1934fce62adbf6141a796ccd9f8ba39641593f674ddb71171cc5ab14 |