Debian Security Advisory
DSA-3840-1 mysql-connector-java -- security update
- Date Reported:
- 02 May 2017
- Affected Packages:
- mysql-connector-java
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-3523.
- More information:
-
Thijs Alkemade discovered that unexpected automatic deserialisation of Java objects in the MySQL Connector/J JDBC driver may result in the execution of arbitary code. For additional details, please refer to the advisory at https://www.computest.nl/advisories/CT-2017-0425_MySQL-Connector-J.txt
For the stable distribution (jessie), this problem has been fixed in version 5.1.41-1~deb8u1.
For the upcoming stable distribution (stretch), this problem has been fixed in version 5.1.41-1.
For the unstable distribution (sid), this problem has been fixed in version 5.1.41-1.
We recommend that you upgrade your mysql-connector-java packages.