Amazon Linux AMI : apache-commons-collections (ALAS-2016-692)

high Nessus Plugin ID 90776

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

As reported upstream, various classes in the functor collection are serialization and use reflection, which could result in arbitrary code execution if objects from untrusted sources are de-serialized.

Solution

Run 'yum update apache-commons-collections' to update your system.

See Also

http://www.nessus.org/u?58bf8e0a

https://alas.aws.amazon.com/ALAS-2016-692.html

Plugin Details

Severity: High

ID: 90776

File Name: ala_ALAS-2016-692.nasl

Version: 2.2

Type: local

Agent: unix

Published: 4/29/2016

Updated: 4/18/2018

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:apache-commons-collections, p-cpe:/a:amazon:linux:apache-commons-collections-javadoc, p-cpe:/a:amazon:linux:apache-commons-collections-testframework, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 4/27/2016

Reference Information

ALAS: 2016-692