FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2015-5254

This CVE name corresponds to:

Entered Topic
2016-03-25 activemq -- Unsafe deserialization

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2015-5254
Phase Assigned(20150701)

Description

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

References

Source Reference
MLIST [oss-security] 20151208 [ANNOUNCE] CVE-2015-5254 - Unsafe deserialization in ActiveMQ
CONFIRM http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt
CONFIRM https://issues.apache.org/jira/browse/AMQ-6013
FEDORA FEDORA-2015-7ca4368b0c
FEDORA FEDORA-2015-eefc5a6762
REDHAT RHSA-2016:0489