<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.rosa.ru/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://bugzilla.rosa.ru/"
          
          maintainer="d.postnikov@rosa.ru"
>

    <bug>
          <bug_id>13869</bug_id>
          
          <creation_ts>2023-10-18 20:26:57 +0300</creation_ts>
          <short_desc>[CVE 21] jackson-dataformats-text 2.9.8  CVEs found</short_desc>
          <delta_ts>2023-12-12 01:43:20 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>2</classification_id>
          <classification>ROSA-based products</classification>
          <product>ROSA Fresh</product>
          <component>System (kernel, glibc, systemd, bash, PAM...)</component>
          <version>All</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc>CVE-2023-3894,</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Highest</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Yury">y.tumanov</reporter>
          <assigned_to name="ROSA Linux Bugs">bugs</assigned_to>
          <cc>e.kosachev</cc>
    
    <cc>s.matveev</cc>
    
    <cc>v.potapov</cc>
    
    <cc>y.tumanov</cc>
          
          <cf_platform>2021.1</cf_platform>
          <cf_security_code></cf_security_code>
          <cf_package></cf_package>
          

      

      

      <flag name="secteam_verified"
          id="14169"
          type_id="2"
          status="?"
          setter="y.tumanov"
    />

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>69757</commentid>
    <comment_count>0</comment_count>
    <who name="Yury">y.tumanov</who>
    <bug_when>2023-10-18 20:26:57 +0300</bug_when>
    <thetext>Please patch CVEs for package jackson-dataformats-text version 2.9.8
  
INFO (CVEs are): jackson-dataformats-text 2.9.8
 cves found
CVE-2023-3894
Desc: Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Link: https://nvd.nist.gov/vuln/detail/CVE-2023-3894
Severity: HIGH</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70194</commentid>
    <comment_count>1</comment_count>
    <who name="Vladimir Potapov">v.potapov</who>
    <bug_when>2023-10-20 17:01:35 +0300</bug_when>
    <thetext>*** Bug 13737 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70196</commentid>
    <comment_count>2</comment_count>
    <who name="Vladimir Potapov">v.potapov</who>
    <bug_when>2023-10-20 17:01:47 +0300</bug_when>
    <thetext>*** Bug 13544 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>71463</commentid>
    <comment_count>3</comment_count>
    <who name="Svyatoslav Matveev">s.matveev</who>
    <bug_when>2023-12-12 01:43:20 +0300</bug_when>
    <thetext>Входит в java-стек, который пока обновляться не будет</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>