xmlrpc3-3.0-4.17.AXS4

エラータID: AXSA:2018-3129:01

Release date: 
Friday, June 1, 2018 - 00:50
Subject: 
xmlrpc3-3.0-4.17.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol that uses XML over HTTP to implement remote procedure calls.

Security Fix(es):

* xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2016-5003
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an element.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. xmlrpc3-3.0-4.17.AXS4.src.rpm
    MD5: 0361160dcbb3dc68323fc146960a1d1b
    SHA-256: f409f68a80e8fbc7c7531340044473a4866c4ca8140f61dcd6856c6f1ede7cf3
    Size: 310.74 kB

Asianux Server 4 for x86
  1. xmlrpc3-client-3.0-4.17.AXS4.noarch.rpm
    MD5: c29637456aa076d061036f3a44758088
    SHA-256: 8dc9fc1dbfb5ce264c4ad934e50b061bc9c2aa5d510ff110eccc8e6676ad5a53
    Size: 42.25 kB
  2. xmlrpc3-common-3.0-4.17.AXS4.noarch.rpm
    MD5: caeb73d7dff4868cd5ca07f949f5b169
    SHA-256: cdfe46e482ba91e52d4ee93fbb8ef9e7c39c2f0ff082f2bf50e6a26bc8a98980
    Size: 90.97 kB

Asianux Server 4 for x86_64
  1. xmlrpc3-client-3.0-4.17.AXS4.noarch.rpm
    MD5: 899599df1eb7b87e10471719c839eeee
    SHA-256: d86d8de851432f4c4105ef3de6e806a44d79bd1e6344eca0654ae65fad0eee92
    Size: 41.80 kB
  2. xmlrpc3-common-3.0-4.17.AXS4.noarch.rpm
    MD5: 36db3c6f134257e1e9058bb6e25b48ec
    SHA-256: 1476ded1a16ab51415e2b4a01ac2775d0e880e6730ad15e661e68bf77ddf4e4d
    Size: 90.52 kB