USN-4774-1: Spring Framework vulnerabilities

17 March 2021

Several security issues were fixed in Spring Framework.

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Learn more about Ubuntu Pro

Releases

Packages

Details

Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)

Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)

It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)

It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified impact. This issue only affected Ubuntu 14.04 ESM.
(CVE-2014-0225)

It was discovered that Spring Framework incorrectly handled certain URLs. A
remote attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack. This issue only affected Ubuntu
14.04 ESM. (CVE-2014-3625, CVE-2014-3578)

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Learn more about Ubuntu Pro

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 16.04
Ubuntu 14.04

In general, a standard system update will make all the necessary changes.