CVE-2017-7957
published 2017-04-29CVE-2017-7957: XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.93%
91.2th percentile
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bamboo_data_center | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxstream-java | < libxstream-java 1.4.9-2 (bookworm) | libxstream-java 1.4.9-2 (bookworm) |
| redhat | fuse | — | — |
| redhat | jboss_middleware | — | — |
| xstream | xstream | <= 1.4.9 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2017-7957: DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server
vendor_atlassian·2024-01-16·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957: DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server
CVE-2017-7957: DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server
DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server
CVE: CVE-2017-7957
Severity: HIGH
Affected products: Bamboo Data Center
Red Hat
XStream: DoS when unmarshalling void type
vendor_redhat·2017-04-03·CVSS 7.5
CVE-2017-7957 [HIGH] CWE-20 XStream: DoS when unmarshalling void type
XStream: DoS when unmarshalling void type
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
It was found that XStream contains a vulnerability that allows a maliciously crafted file to be parsed successfully which could cause an application crash. The crash occurs if the file that is being fed into XStream input stream contains an instances of the primitive type 'void'. An attacker could use this flaw to create a denial of service on the target system.
Package: xstream (Red Hat BPM Suite 6) - Affected
Package: xstream (Red Hat Enterprise Linux 7) - Affected
Package: jasperreports-server
Debian
CVE-2017-7957: libxstream-java - XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandl...
vendor_debian·2017·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957: libxstream-java - XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandl...
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
Scope: local
bookworm: resolved (fixed in 1.4.9-2)
bullseye: resolved (fixed in 1.4.9-2)
forky: resolved (fixed in 1.4.9-2)
sid: resolved (fixed in 1.4.9-2)
trixie: resolved (fixed in 1.4.9-2)
GHSA
Denial of service in XStream
ghsa·2020-06-30
CVE-2017-7957 [HIGH] CWE-20 Denial of service in XStream
Denial of service in XStream
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
OSV
Denial of service in XStream
osv·2020-06-30
CVE-2017-7957 [HIGH] Denial of service in XStream
Denial of service in XStream
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
OSV
CVE-2017-7957: XStream through 1
osv·2017-04-29·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957: XStream through 1
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
bugzilla·2018-07-05·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
bugzilla·2017-08-14·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type
bugzilla·2017-04-12·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957 XStream: DoS when unmarshalling void type
CVE-2017-7957 XStream: DoS when unmarshalling void type
A vulnerability was found in XStream. Parsing a maliciously crafted file could cause the application to crash.
The processed stream at unmarshalling type contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. The crash occurrs if this information advices XStream to create an instance of the primitive type 'void'. This situation can only happen if an attacker was able to manipulate the incoming data, since such an instance does not exist.
References:
http://seclists.org/oss-sec/2017/q2/9
Discussion:
Created jenkins-xstream tracking bugs for this issue:
Affects: fedora-all [bug 1441541]
Created xstream tracking bugs for this issue:
Affects: f
Bugzilla
CVE-2017-7957 jenkins-xstream: XStream: DoS when unmarshalling void type [fedora-all]
bugzilla·2017-04-12·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957 jenkins-xstream: XStream: DoS when unmarshalling void type [fedora-all]
CVE-2017-7957 jenkins-xstream: XStream: DoS when unmarshalling void type [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
bugzilla·2017-04-12·CVSS 7.5
CVE-2017-7957 [HIGH] CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
http://www.debian.org/security/2017/dsa-3841http://www.securityfocus.com/bid/100687http://www.securitytracker.com/id/1039499http://x-stream.github.io/CVE-2017-7957.htmlhttps://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2017:2888https://access.redhat.com/errata/RHSA-2017:2889https://exchange.xforce.ibmcloud.com/vulnerabilities/125800https://www-prd-trops.events.ibm.com/node/715749http://www.debian.org/security/2017/dsa-3841http://www.securityfocus.com/bid/100687http://www.securitytracker.com/id/1039499http://x-stream.github.io/CVE-2017-7957.htmlhttps://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2017:2888https://access.redhat.com/errata/RHSA-2017:2889https://exchange.xforce.ibmcloud.com/vulnerabilities/125800https://www-prd-trops.events.ibm.com/node/715749
2017-04-29
Published