Oval Definition:oval:com.redhat.rhsa:def:20172486
Revision Date:2017-08-17Version:637
Title:RHSA-2017:2486: groovy security update (Important)
Description:Groovy is an agile and dynamic language for the Java Virtual Machine, built upon Java with features inspired by languages like Python, Ruby, and Smalltalk. It seamlessly integrates with all existing Java objects and libraries and compiles straight to Java bytecode so you can use it anywhere you can use Java.

Security Fix(es):

  • It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability. (CVE-2016-6814)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-3253
    CVE-2016-6814
    RHSA-2017:2486
    RHSA-2017:2486-00
    RHSA-2017:2486-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • groovy is earlier than 0:1.8.9-8.el7_4
  • AND groovy is signed with Red Hat redhatrelease2 key
  • groovy-javadoc is earlier than 0:1.8.9-8.el7_4
  • AND groovy-javadoc is signed with Red Hat redhatrelease2 key
  • BACK