[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2018:1837-01 -- Redhat rh-maven33-plexus-archiver, rh-maven35-plexus-archiver

ID: oval:org.secpod.oval:def:504925Date: (C)2021-01-29   (M)2023-08-10
Class: PATCHFamily: unix




The Plexus project provides a full software stack for creating and executing software projects. Based on the Plexus container, the applications can utilise component-oriented programming to build modular, reusable components that can easily be assembled and reused. The plexus-archiver component provides functions to create and extract archives. Security Fix: * plexus-archiver: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Red Hat would like to thank Danny Grander for reporting this issue.

Platform:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Product:
rh-maven33-plexus-archiver
rh-maven35-plexus-archiver
Reference:
RHSA-2018:1837-01
CVE-2018-1002200
CVE    1
CVE-2018-1002200
CPE    4
cpe:/a:redhat:rh-maven35-plexus-archiver
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:6
cpe:/a:redhat:rh-maven33-plexus-archiver
...

© SecPod Technologies