Oval Definition:oval:com.ubuntu.xenial:def:201552110000000
Revision Date:2017-05-25Version:1
Title:CVE-2015-5211 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response. It was discovered that Spring Framework incorrectly handled certain URLs. A remote attacker could possibly use this issue to cause a reflected file download.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-5211
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND libspring-java package in xenial is affected and needs fixing.
  • BACK