Description: | Summary: The remote host is missing an update for the 'libspring-java' package(s) announced via the USN-4774-1 advisory.
Vulnerability Insight: Toshiaki Maki discovered that Spring Framework incorrectly handled certain XML files. A remote attacker could exploit this with a crafted XML file to cause a denial of service. (CVE-2015-3192)
Alvaro Munoz discovered that Spring Framework incorrectly handled certain URLs. A remote attacker could possibly use this issue to cause a reflected file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path inputs. An attacker could possibly use this issue to read arbitrary files, resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents. An attacker could possibly use this issue to generate an XML external entity attack, resulting in a denial of service, disclosure of information or other unspecified impact. This issue only affected Ubuntu 14.04 ESM. (CVE-2014-0225)
It was discovered that Spring Framework incorrectly handled certain URLs. A remote attacker could possibly use this issue to read arbitrary files, resulting in a directory traversal attack. This issue only affected Ubuntu 14.04 ESM. (CVE-2014-3625, CVE-2014-3578)
Affected Software/OS: 'libspring-java' package(s) on Ubuntu 14.04, Ubuntu 16.04.
Solution: Please install the updated package(s).
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|