Oval Definition:oval:org.opensuse.security:def:111099
Revision Date:2021-01-22Version:1
Title:Security update for xstream (Important)
Description:

This update for xstream fixes the following issues:

xstream was updated to version 1.4.15.

- CVE-2020-26217: Fixed a remote code execution due to insecure XML deserialization when relying on blocklists (bsc#1180994). - CVE-2020-26258: Fixed a server-side request forgery vulnerability (bsc#1180146). - CVE-2020-26259: Fixed an arbitrary file deletion vulnerability (bsc#1180145).

This update was imported from the SUSE:SLE-15-SP2:Update update project.
Family:unixClass:patch
Status:Reference(s):1180145
1180146
1180994
CVE-2020-26217
CVE-2020-26258
CVE-2020-26259
openSUSE-SU-2021:0140-1
Platform(s):openSUSE Leap 15.2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • xstream-1.4.15-lp152.2.3.1 is installed
  • OR xstream-benchmark-1.4.15-lp152.2.3.1 is installed
  • OR xstream-javadoc-1.4.15-lp152.2.3.1 is installed
  • OR xstream-parent-1.4.15-lp152.2.3.1 is installed
  • BACK