UBUNTU-CVE-2017-5878

Source
https://ubuntu.com/security/CVE-2017-5878
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-5878.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-5878
Upstream
  • CVE-2017-5878
Published
2017-06-08T16:29:00Z
Modified
2025-10-24T04:46:10Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.

References

Affected packages

Ubuntu:16.04:LTS / red5

Package

Name
red5
Purl
pkg:deb/ubuntu/red5@1.0~svn4374-4.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0~svn4374-4
1.0~svn4374-4.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libred5-java",
            "binary_version": "1.0~svn4374-4.1"
        },
        {
            "binary_name": "red5-server",
            "binary_version": "1.0~svn4374-4.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-5878.json"