CVE-2016-4000
CRITICAL9.8EPSS 12.5%Deserialization of Untrusted Data in Jython
發布日:2022/5/13修改日:2026/4/28
描述
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
受影響套件(5)
- Debian/jythonfrom 0, < 2.5.3-17
- Debian/jythonfrom 0, < 2.5.2-1+deb7u1
- Debian/jythonfrom 0, < 2.5.3-3+deb8u1
- Maven/org.python:jythonfrom 0, < 2.7.1-rc1
- Maven/org.python:jython-standalonefrom 0, < 2.7.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(17)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-4000
- WEBhttp://bugs.jython.org/issue2454
- WEBhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864859
- WEBhttps://hg.python.org/jython/file/v2.7.1rc1/NEWS
- WEBhttps://hg.python.org/jython/rev/d06e29d100c0
- WEBhttps://lists.apache.org/thread.html/0919ec1db20b1022f22b8e78f355667df74d6142b463ff17d03ad533@%3Cdevnull.infra.apache.org%3E
- WEBhttps://security.gentoo.org/glsa/201710-28
- WEBhttps://security-tracker.debian.org/tracker/CVE-2016-4000
- WEBhttps://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451
- WEBhttps://www.oracle.com/security-alerts/cpuapr2020.html
- WEBhttps://www.oracle.com/security-alerts/cpujan2020.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2020.html
- WEBhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- WEBhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- WEBhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- WEBhttp://www.debian.org/security/2017/dsa-3893
- WEBhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html