MGASA-2022-0340

Source
https://advisories.mageia.org/MGASA-2022-0340.html
Import Source
https://advisories.mageia.org/MGASA-2022-0340.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0340
Related
Published
2022-09-21T18:15:27Z
Modified
2022-09-21T17:17:06Z
Summary
Updated google-gson packages fix security vulnerability
Details

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. (CVE-2022-25647)

References
Credits

Affected packages

Mageia:8 / google-gson

Package

Name
google-gson
Purl
pkg:rpm/mageia/google-gson?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.6-1.1.mga8

Ecosystem specific

{
    "section": "core"
}