Debian 9894 Published by

The following updates has been released for Debian GNU/Linux 8 LTS:

DLA 1753-3: proftpd-dfsg regression update
DLA 1798-1: jackson-databind security update



DLA 1753-3: proftpd-dfsg regression update




Package : proftpd-dfsg
Version : 1.3.5e+r1.3.5-2+deb8u2
Debian Bug : 929020

The update of proftpd-dfsg issued as DLA-1753-1 caused a regression
when the creation of a directory failed during sftp transfer. The sftp
session would be terminated instead of failing gracefully due to a
non-existing debug logging function.

For Debian 8 "Jessie", this problem has been fixed in version
1.3.5e+r1.3.5-2+deb8u2.

We recommend that you upgrade your proftpd-dfsg packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


DLA 1798-1: jackson-databind security update




Package : jackson-databind
Version : 2.4.2-2+deb8u6
CVE ID : CVE-2019-12086
Debian Bug : 929177

A Polymorphic Typing issue was discovered in jackson-databind, a JSON
library for Java. When Default Typing is enabled (either globally or
for a specific property) for an externally exposed JSON endpoint, the
service has the mysql-connector-java jar (8.0.14 or earlier) in the
classpath, and an attacker can host a crafted MySQL server reachable
by the victim, an attacker can send a crafted JSON message that allows
them to read arbitrary local files on the server. This occurs because of
missing com.mysql.cj.jdbc.admin.MiniAdmin validation.


For Debian 8 "Jessie", this problem has been fixed in version
2.4.2-2+deb8u6.

We recommend that you upgrade your jackson-databind packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS