CVE-2016-4000

NameCVE-2016-4000
DescriptionJython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-989-1, DSA-3893-1
Debian Bugs864859

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jython (PTS)jessie, jessie (lts)2.5.3-3+deb8u1fixed
stretch (security), stretch (lts), stretch2.5.3-16+deb9u1fixed
buster2.7.1+repack1-4~deb10u1fixed
bullseye2.7.2+repack1-3fixed
sid, trixie, bookworm2.7.3+repack1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jythonsourcewheezy2.5.2-1+deb7u1DLA-989-1
jythonsourcejessie2.5.3-3+deb8u1DSA-3893-1
jythonsourcestretch2.5.3-16+deb9u1DSA-3893-1
jythonsource(unstable)2.5.3-17864859

Notes

http://bugs.jython.org/issue2454
https://hg.python.org/jython/rev/d06e29d100c0

Search for package or bug name: Reporting problems