Scientific Linux alert SLSA-2021:0162-1 (xstream)
From: | Pat Riehecky <riehecky@fnal.gov> | |
To: | scientific-linux-errata@listserv.fnal.gov | |
Subject: | Security ERRATA Important: xstream on SL7.x (noarch) | |
Date: | Tue, 26 Jan 2021 16:08:25 -0000 | |
Message-ID: | <20210126160825.28767.35532@slpackages.fnal.gov> |
Synopsis: Important: xstream security update Advisory ID: SLSA-2021:0162-1 Issue Date: 2021-01-19 CVE Numbers: CVE-2020-26217 -- Security Fix(es): * XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) -- SL7 noarch xstream-1.3.1-12.el7_9.noarch.rpm xstream-javadoc-1.3.1-12.el7_9.noarch.rpm - Scientific Linux Development Team