Redhat released their fixed rpm referencing CVE-2015-7501
(RHSA-2015:2521). It looks like they cherrypicked the
COLLECTIONS-580.patch and released it as jakarta-commons-collections
0:3.2.1-3.5.el6_7.

As usual, MITRE still has CVE-2015-7501 as "reserved".

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2015-7501

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1514985

Title:
  Arbitrary remote code execution with InvokerTransformer

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libcommons-collections3-java/+bug/1514985/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to