USN-6936-1: Apache Commons Collections vulnerability
31 July 2024
Apache Commons Collections could be made to execute arbitrary code if it received specially crafted input.
Releases
Packages
- libcommons-collections3-java - Apache Commons Collections - Extended Collections API for Java
Details
It was discovered that Apache Commons Collections allowed serialization
support for unsafe classes by default. A remote attacker could possibly
use this issue to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04
-
libcommons-collections3-java
-
3.2.1-6ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.