CVE-2016-4000
CVE-2016-4000
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.jython.org/issue2454https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864859https://hg.python.org/jython/file/v2.7.1rc1/NEWShttps://hg.python.org/jython/rev/d06e29d100c0https://lists.apache.org/thread.html/0919ec1db20b1022f22b8e78f355667df74d6142b463ff17d03ad533%40%3Cdevnull.infra.apache.org%3Ehttps://security.gentoo.org/glsa/201710-28https://security-tracker.debian.org/tracker/CVE-2016-4000https://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html