Debian Security Advisory
DLA-1662-1 libthrift-java -- LTS security update
- Date Reported:
- 06 Feb 2019
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 918736.
In Mitre's CVE dictionary: CVE-2018-1320.
- More information:
It was discovered that it was possible to bypass SASL negotiation isComplete validation in libthrift-java, Java language support for the Apache Thrift software framework. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
For Debian 8
Jessie, this problem has been fixed in version 0.9.1-2+deb8u1.
We recommend that you upgrade your libthrift-java packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS