Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://x-stream.github.io/changes.html#1.4.9 | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html | vendor advisory broken link third party advisory |
http://www.debian.org/security/2016/dsa-3575 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2016-2822.html | vendor advisory broken link |
http://www.securityfocus.com/bid/85381 | third party advisory vdb entry |
http://www.securitytracker.com/id/1036419 | third party advisory vdb entry |
http://www.openwall.com/lists/oss-security/2016/03/28/1 | third party advisory mailing list |
http://rhn.redhat.com/errata/RHSA-2016-2823.html | vendor advisory broken link |
https://github.com/x-stream/xstream/issues/25 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/03/25/8 | third party advisory mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.html | vendor advisory broken link third party advisory |