Oval Definition:oval:com.ubuntu.precise:def:20164974000
Revision Date:2016-07-13Version:1
Title:CVE-2016-4974 on Ubuntu 12.04 LTS (precise) - medium.
Description:Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-4974
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The vulnerability of the 'qpid-cpp' package in precise is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK