CVE-2022-41966
Publication date 28 December 2022
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only as default map or set, is to change the default implementation of java.util.Map and java.util per the code example in the referenced advisory. However, this implies that your application does not care about the implementation of the map and all elements are comparable.
Status
Package | Ubuntu Release | Status |
---|---|---|
libxstream-java | 24.10 oracular |
Needs evaluation
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Fixed 1.4.18-2ubuntu0.1
|
|
20.04 LTS focal |
Fixed 1.4.11.1-1ubuntu0.3
|
|
18.04 LTS bionic |
Fixed 1.4.11.1-1+deb10u4build0.18.04.1
|
|
16.04 LTS xenial |
Fixed 1.4.8-1ubuntu0.1+esm1
|
|
14.04 LTS trusty |
Fixed 1.4.7-1ubuntu0.1+esm1
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-5946-1
- XStream vulnerabilities
- 13 March 2023