USN-4943-1

Source
https://ubuntu.com/security/notices/USN-4943-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4943-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4943-1
Related
Published
2021-05-11T09:41:13.712555Z
Modified
2021-05-11T09:41:13.712555Z
Summary
libxstream-java vulnerabilities
Details

Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code execution. A remote attacker could run arbitrary shell commands by manipulating the processed input stream. This issue affected only affected Ubuntu 20.10. (CVE-2020-26217)

It was discovered that XStream was vulnerable to server-side forgery attacks. A remote attacker could request data from internal resources that are not publicly available only by manipulating the processed input stream. This issue only affected Ubuntu 20.10. (CVE-2020-26258)

It was discovered that XStream was vulnerable to arbitrary file deletion on the local host. A remote attacker could use this to delete arbitrary known files on the host as long as the executing process had sufficient rights only by manipulating the processed input stream. This issue only affected Ubuntu 20.10. (CVE-2020-26259)

It was discovered that XStream was vulnerable to denial of service, arbitrary code execution, arbitrary file deletion and server-side forgery attacks. A remote attacker could cause any of those issues by manipulating the processed input stream. (CVE-2021-21341, CVE-2021-21342, CVE-2021-21343 CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351)

References

Affected packages

Ubuntu:18.04:LTS / libxstream-java

Package

Name
libxstream-java
Purl
pkg:deb/ubuntu/libxstream-java?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.11.1-1~18.04.2

Affected versions

1.*

1.4.10-1
1.4.11.1-1~18.04
1.4.11.1-1~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.4.11.1-1~18.04.2",
            "binary_name": "libxstream-java"
        }
    ]
}

Ubuntu:20.04:LTS / libxstream-java

Package

Name
libxstream-java
Purl
pkg:deb/ubuntu/libxstream-java?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.11.1-1ubuntu0.2

Affected versions

1.*

1.4.11.1-1
1.4.11.1-1ubuntu0.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.4.11.1-1ubuntu0.2",
            "binary_name": "libxstream-java"
        }
    ]
}