Debian Security Advisory

DLA-1943-1 jackson-databind -- LTS security update

Date Reported:
03 Oct 2019
Affected Packages:
jackson-databind
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 940498, Bug 941530.
In Mitre's CVE dictionary: CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.
More information:

More deserialization flaws were discovered in jackson-databind relating to the classes in com.zaxxer.hikari.HikariConfig, com.zaxxer.hikari.HikariDataSource, commons-dbcp and com.p6spy.engine.spy.P6DataSource, which could allow an unauthenticated user to perform remote code execution. The issue was resolved by extending the blacklist and blocking more classes from polymorphic deserialization.

For Debian 8 Jessie, these problems have been fixed in version 2.4.2-2+deb8u9.

We recommend that you upgrade your jackson-databind packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS