Vulnerability Description
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qos | Logback | < 1.2.0 |
| Redhat | Satellite | 6.4 |
| Redhat | Satellite Capsule | 6.4 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2017:1675Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1676Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1832Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2927Third Party Advisory
- https://lists.apache.org/thread.html/18d509024d9aeb07f0e9579066f80bf5d4dcf20467b
- https://lists.apache.org/thread.html/a6db61616180d73711d6db25703085940026e2dbc40
- https://lists.apache.org/thread.html/fa4eaaa6ff41ac6f79811e053c152ee89b7c5da8a6a
- https://lists.apache.org/thread.html/r0bb19330e48d5ad784fa20dacba9e5538d8d60f5cd
- https://lists.apache.org/thread.html/r2a08573ddee4a86dc96d469485a5843a01710ee0dc
- https://lists.apache.org/thread.html/r2c2d57ca180e8173c90fe313ddf8eabbdcf8e3ae19
- https://lists.apache.org/thread.html/r397bf63783240fbb5713389d3f889d287ae0c11509
- https://lists.apache.org/thread.html/r4673642893562c58cbee60c151ded6c077e8a2d022
- https://lists.apache.org/thread.html/r632ec30791b441e2eb5a3129532bf1b689bf181d0e
- https://lists.apache.org/thread.html/r718f27bed898008a8e037d9cc848cfc1df4d18abcb
- https://lists.apache.org/thread.html/r967953a14e05016bc4bcae9ef3dd92e770181158b4
FAQ
What is CVE-2017-5929?
CVE-2017-5929 is a vulnerability with a CVSS score of 9.8 (CRITICAL). QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
How severe is CVE-2017-5929?
CVE-2017-5929 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5929?
Check the references section above for vendor advisories and patch information. Affected products include: Qos Logback, Redhat Satellite, Redhat Satellite Capsule.