Debian 10020 Published by

A bcel security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address an integer truncation issue.



ELA-707-1 bcel security update

Package bcel
Version 6.0~rc3-1+deb8u1 (jessie), 6.0-1+deb9u1 (stretch)
Related CVEs CVE-2022-34169

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. In Debian the vulnerable code is in the bcel source package.

For Debian 8 jessie, these problems have been fixed in version 6.0~rc3-1+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 6.0-1+deb9u1.

We recommend that you upgrade your bcel packages.

Further information about Extended LTS security advisories can be found at: debian Extended Long term support

  ELA-707-1 bcel security update