oss-sec mailing list archives
Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw
From: "Lisa Bradley" <lbradley () us ibm com>
Date: Fri, 13 Nov 2015 11:14:59 -0500
Seems Oracle has a CVE for this: https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852 ~Lisa Lisa Wood Bradley, PhD Team Lead | Product Security Incident Response Team (PSIRT) SWG Master Inventor Work: (720) 396-3787 T/L: 938-3787 Cell: (919) 656-1608 lbradley () us ibm com WFH Cary, NC From: Mark Felder <feld () feld me> To: oss-security () lists openwall com Date: 11/13/2015 09:38 AM Subject: Re: [oss-security] CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw On Fri, Nov 13, 2015, at 01:58, Gsunde Orangen wrote:
I share Tim's view [2] and a dozen of (own) applications we checked won't break. A property that re-enables deserialization of course would help additionally: allow applications that really *need* this to get it working; but that requires an explicit step - so latest by that time: those, whose applications break after including a "fixed" version of Commons-Collections would (hopefully) start to think about their design. Gsunde [1] http://seclists.org/oss-sec/2015/q4/238 [2] http://seclists.org/oss-sec/2015/q4/263
This statement is how we have been operating our mitigation strategy: "Applications which use Apache Commons Collections and do not use deserialization are not vulnerable." Assuming that statement is correct, disabling deserialization by default doesn't offer additional protection to people. Instead it requires a code change when they upgrade to re-enable it and cause them to be vulnerable again. Would the greater community be better served by additional documentation on how to safely handle the deserialization in their application? Is there such a method, or is this hopelessly broken? If you're still vulnerable even if you don't use deserialization in your application this completely changes our risk profile and we need to change our mitigation strategy. -- Mark Felder feld () feld me
Current thread:
- Re: Assign CVE for common-collections remote code execution on deserialisation flaw, (continued)
- Re: Assign CVE for common-collections remote code execution on deserialisation flaw Tim (Nov 10)
- Re: Assign CVE for common-collections remote code execution on deserialisation flaw Moritz Bechler (Nov 11)
- Re: Assign CVE for common-collections remote code execution on deserialisation flaw Tim (Nov 11)
- CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 12)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Mark Felder (Nov 12)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Tim (Nov 12)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Mark Felder (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Tim (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 12)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Mark Felder (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Lisa Bradley (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Oracle Security Alerts (Thomas) (Nov 17)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Mark Felder (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 13)
- Re: CVE-Request: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 15)
- Re: Re: Assign CVE for common-collections remote code execution on deserialisation flaw Gsunde Orangen (Nov 13)