Release date:
Updated on:
Affected Systems:
Restlet 2.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4221
Restlet is a Java web API framework.
Restlet 2.1.2 Uses the XMLDecoder class to deserialize user-controlled XML data and binary data. This allows remote attackers to execute arbitrary Java code by submitting specially crafted XML data or binary data, or call any deserialization method on the Java object.
<* Source: Dinis Cruz
Abraham Kang
Alvaro Munoz
Link: http://secunia.com/advisories/53677/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Restlet
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://restlet.org/
Http://restlet.org/learn/2.1/changes
Https://github.com/restlet/restlet-framework-java/issues/774
Https://github.com/restlet/restlet-framework-java/issues/778