RHSA-2017:1840: Important: devtoolset-4-jackson-databind security update
The jackson-databind package provides general data-binding functionality for Jackson, which works on top of Jackson core streaming API.Security Fix(es): A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. (CVE-2017-7525) Red Hat would like to thank Liao Xinxi (NSFOCUS) for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:1840?
RHSA-2017:1840 is classified as important.
How do I fix RHSA-2017:1840?
To fix RHSA-2017:1840, upgrade to the recommended version of 4-jackson-databind as specified in the advisory.
What vulnerability does RHSA-2017:1840 address?
RHSA-2017:1840 addresses a deserialization flaw in the jackson-databind package.
Who is affected by RHSA-2017:1840?
RHSA-2017:1840 affects users running the specified versions of the jackson-databind package on Red Hat systems.
Is there a workaround for RHSA-2017:1840?
There are no effective workarounds for RHSA-2017:1840, so applying the update is necessary.