Vulnerability Bulletins

DSA-3504 bsh - security update

   
Affected software Debian
 
Alvaro Muñoz and Christian Schneider discovered that BeanShell, anembeddable Java source interpreter, could be leveraged to executearbitrary commands: applications including BeanShell in theirclasspath are vulnerable to this flaw if they deserialize data from anuntrusted source.

More info:

https://www.debian.org/security/2016/dsa-3504