XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-29T19:00:00

Updated: 2024-08-05T16:19:29.479Z

Reserved: 2017-04-19T00:00:00

Link: CVE-2017-7957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-29T19:59:00.167

Modified: 2019-03-26T17:15:49.980

Link: CVE-2017-7957

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-04-03T00:00:00Z

Links: CVE-2017-7957 - Bugzilla