Input validation error in jackson-databind - CVE-2018-1000873

 

Input validation error in jackson-databind - CVE-2018-1000873

Published: January 4, 2019


Vulnerability identifier: #VU16786
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000873
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into deserializing of crafted input with specifically very large values in the nanoseconds field of a time value and cause the service to crash.


Affected software

jackson-databind
Cloudera Observability with IBM
Dell Support Assist Enterprise
B2B Advanced Communications
Multi-Enterprise Integration Gateway
Storage Defender Copy Data Management
StreamSets Data Collector
IBM InfoSphere Information Server
Oracle Clusterware
Fedora
bouncycastle
jackson-parent
jackson-dataformats-text
jackson-modules-base
jackson-module-jsonSchema
jackson-jaxrs-providers
jackson-datatypes-collections
jackson-datatype-joda
jackson-datatype-jdk8
jackson-dataformats-binary
jackson-dataformat-xml
jackson-databind
jackson-core
jackson-bom
jackson-annotations
eclipse-jgit
eclipse-linuxtools

How to mitigate CVE-2018-1000873

Update to version 2.9.8.

jackson-databind - update to 2.9.8
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
bouncycastle - update to 1.61-1.fc29
Storage Defender Copy Data Management - update to 2.2.28.0
jackson-parent - update to 2.9.1.2-1.fc29
jackson-dataformats-text - update to 2.9.8-1.fc29
jackson-modules-base - update to 2.9.8-1.fc29
jackson-module-jsonSchema - update to 2.9.8-1.fc29
jackson-jaxrs-providers - update to 2.9.8-1.fc29
jackson-datatypes-collections - update to 2.9.8-1.fc29
jackson-datatype-joda - update to 2.9.8-1.fc29
jackson-datatype-jdk8 - update to 2.9.8-1.fc29
jackson-dataformats-binary - update to 2.9.8-1.fc29
jackson-dataformat-xml - update to 2.9.8-1.fc29
jackson-databind - update to 2.9.8-1.fc29
jackson-core - update to 2.9.8-1.fc29
jackson-bom - update to 2.9.8-1.fc29
jackson-annotations - update to 2.9.8-1.fc29
eclipse-jgit - update to 5.2.0-4.fc29
StreamSets Data Collector - update to 7.0.0
eclipse-linuxtools - update to 7.1.0-3.fc29

External References

Related Security Bulletins