QID 198361

Date Published: 2021-05-17

QID 198361: Ubuntu Security Notification for XStream vulnerabilities (USN-4943-1)

It was discovered that XStream was vulnerable to denial of service, arbitrary code execution, arbitrary file deletion, and server-side forgery attacks.

A remote attacker could request data from internal resources that are not publicly available only by manipulating the processed input stream
This issue only affected Ubuntu 2010
(CVE-2020-26258)

A remote attacker could request data from internal resources that are not publicly available only by manipulating the processed input stream. This issue only affected Ubuntu 20.10. (CVE-2020-26258)

A remote attacker could use this to delete arbitrary known files on the host as long as the executing process had sufficient rights only by manipulating the processed input stream. This issue only affected Ubuntu 20.10. (CVE-2020-26259)

A remote attacker could cause any of those issues by manipulating the processed input stream. (CVE-2021-21341, CVE-2021-21342, CVE-2021-21343 CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351)

  • CVSS V3 rated as Critical - 9.9 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4943-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4943-1 Ubuntu Linux URL Logo usn.ubuntu.com/4943-1