USN-4774-1: Spring Framework vulnerabilities

Publication date

17 March 2021

Overview

Several security issues were fixed in Spring Framework.


Packages

Details

Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)

Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)

It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)

It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified...

Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)

Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)

It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)

It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified impact. This issue only affected Ubuntu 14.04 ESM.
(CVE-2014-0225)

It was discovered that Spring Framework incorrectly handled certain URLs. A
remote attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack. This issue only affected Ubuntu
14.04 ESM. (CVE-2014-3625, CVE-2014-3578)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
16.04 xenial libspring-aop-java –  3.2.13-5ubuntu0.1~esm1  
libspring-web-portlet-java –  3.2.13-5ubuntu0.1~esm1  
libspring-core-java –  3.2.13-5ubuntu0.1~esm1  
libspring-oxm-java –  3.2.13-5ubuntu0.1~esm1  
libspring-beans-java –  3.2.13-5ubuntu0.1~esm1  
libspring-jms-java –  3.2.13-5ubuntu0.1~esm1  
libspring-expression-java –  3.2.13-5ubuntu0.1~esm1  
libspring-transaction-java –  3.2.13-5ubuntu0.1~esm1  
libspring-orm-java –  3.2.13-5ubuntu0.1~esm1  
libspring-context-java –  3.2.13-5ubuntu0.1~esm1  
libspring-web-servlet-java –  3.2.13-5ubuntu0.1~esm1  
libspring-instrument-java –  3.2.13-5ubuntu0.1~esm1  
libspring-context-support-java –  3.2.13-5ubuntu0.1~esm1  
libspring-jdbc-java –  3.2.13-5ubuntu0.1~esm1  
libspring-web-java –  3.2.13-5ubuntu0.1~esm1  
14.04 trusty libspring-aop-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-web-struts-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-web-portlet-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-core-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-oxm-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-beans-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-jms-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-expression-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-transaction-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-orm-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-context-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-web-servlet-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-instrument-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-context-support-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-jdbc-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  
libspring-web-java –  3.0.6.RELEASE-13ubuntu0.1~esm2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›