MGASA-2016-0175

Source
https://advisories.mageia.org/MGASA-2016-0175.html
Import Source
https://advisories.mageia.org/MGASA-2016-0175.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0175
Related
Published
2016-05-13T21:54:49Z
Modified
2016-05-13T21:48:30Z
Summary
Updated jackson-dataformat-xml packages fix CVE-2016-3720
Details

Updated jackson-dataformat-xml packages fix security vulnerability:

It was reported that XmlMapper in jackson-dataformat-xml is vulnerable to XXE attack ("Improper Restriction of XML External Entity Reference") (CVE-2016-3720).

References
Credits

Affected packages

Mageia:5 / jackson-dataformat-xml

Package

Name
jackson-dataformat-xml
Purl
pkg:rpm/mageia/jackson-dataformat-xml?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.3-3.1.mga5

Ecosystem specific

{
    "section": "core"
}