Debian Security Advisory

DSA-3840-1 mysql-connector-java -- security update

Date Reported:
02 May 2017
Affected Packages:
mysql-connector-java
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-3523.
More information:

Thijs Alkemade discovered that unexpected automatic deserialisation of Java objects in the MySQL Connector/J JDBC driver may result in the execution of arbitary code. For additional details, please refer to the advisory at https://www.computest.nl/advisories/CT-2017-0425_MySQL-Connector-J.txt

For the stable distribution (jessie), this problem has been fixed in version 5.1.41-1~deb8u1.

For the upcoming stable distribution (stretch), this problem has been fixed in version 5.1.41-1.

For the unstable distribution (sid), this problem has been fixed in version 5.1.41-1.

We recommend that you upgrade your mysql-connector-java packages.