This bug was fixed in the package jython - 2.5.3-1ubuntu0.1
---------------
jython (2.5.3-1ubuntu0.1) trusty-security; urgency=high
[ Simon Quigley ]
* SECURITY UPDATE: Creates executables class files with wrong permissions
(LP: #1714728)
- CVE-2013-2027
- 1-CVE-2013-2027.patch
- 2-CVE-2013-2027.patch
- 3-CVE-2013-2027.patch
- Thanks to Lubomir Rintel for the patches!
[ Markus Koschany ]
* SECURITY UPDATE: Unsafe deserialization may lead to arbitrary code
execution
- CVE-2016-4000
- CVE-2016-4000.patch
-- Simon Quigley <[email protected]> Wed, 20 Sep 2017 21:10:50 -0500
** Changed in: jython (Ubuntu Trusty)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1714728
Title:
[CVEs] Creates executables class files with wrong permissions, Unsafe
deserialization leads to code execution
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jython/+bug/1714728/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs