From 7785404bd292918a4afd4780ccfc36d6626a49ca Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 31 Oct 2022 03:04:34 +0000 Subject: gentoo auto-resync : 31:10:2022 - 03:04:34 --- metadata/glsa/glsa-202210-21.xml | 43 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 metadata/glsa/glsa-202210-21.xml (limited to 'metadata/glsa/glsa-202210-21.xml') diff --git a/metadata/glsa/glsa-202210-21.xml b/metadata/glsa/glsa-202210-21.xml new file mode 100644 index 000000000000..048f9d1f3816 --- /dev/null +++ b/metadata/glsa/glsa-202210-21.xml @@ -0,0 +1,43 @@ + + + + FasterXML jackson-databind: Multiple vulnerabilities + Multiple vulnerabilities have been found in FasterXML jackson-databind, the worst of which could result in denial of service. + jackson-databind + 2022-10-31 + 2022-10-31 + 874033 + remote + + + 2.13.4.1 + 2.13.4.1 + + + +

FasterXML jackson-databind is a general data-binding package for Jackson (2.x) which works on streaming API (core) implementation(s).

+
+ +

Multiple vulnerabilities have been discovered in FasterXML jackson-databind. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All FasterXML jackson-databind users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-java/jackson-databind-2.13.4.1" + +
+ + CVE-2022-42003 + CVE-2022-42004 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3