Oval Definition:oval:com.ubuntu.bionic:def:201552110000000
Revision Date:2017-05-25Version:1
Title:CVE-2015-5211 on Ubuntu 18.04 LTS (bionic) - medium.
Description:Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response. It was discovered that Spring Framework incorrectly handled certain URLs. A remote attacker could possibly use this issue to cause a reflected file download.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-5211
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND libspring-java package in bionic, is related to the CVE in some way and has been fixed (note: '4.3.14-1').
  • BACK