Bug 967593 (CVE-2016-2510) - VUL-0: CVE-2016-2510: bsh2: remote code execution vulnerability via deserialization
Summary: VUL-0: CVE-2016-2510: bsh2: remote code execution vulnerability via deseriali...
Status: RESOLVED FIXED
Alias: CVE-2016-2510
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/162077/
Whiteboard: CVSSv2:SUSE:CVE-2016-2510:9.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-22 09:04 UTC by Alexander Bergmann
Modified: 2016-04-19 09:34 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-02-22 09:04:41 UTC
New beanshell release 2.0b6 fixes a remote code execution vulnerability.

https://github.com/beanshell/beanshell/releases/tag/2.0b6

This affects only SDK releases. Released with products:
* sle-sdk 11.0 (L3: false)
* sle-sdk 11.1 (L3: false)
* sle-sdk 11.2 (L3: false)
* sle-sdk 11.3 (L3: false)
* sle-sdk 11.4 (L3: false)
* sle-sdk 12.0 (L3: false)
* sle-sdk 12.1 (L3: false)

Upstream Patches:
https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49
https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2ced

CVE-2016-2510 was assigned to this issue.




References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2510
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2510.html
Comment 1 Alexander Bergmann 2016-02-22 09:10:52 UTC
And affects openSUSE 13.2 and Leap 42.1.
Comment 2 Tomáš Chvátal 2016-02-23 17:48:04 UTC
Update sent to Factory.
Comment 3 Bernhard Wiedemann 2016-02-23 18:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (967593) was mentioned in
https://build.opensuse.org/request/show/361161 Factory / bsh2
Comment 4 Tomáš Chvátal 2016-02-23 18:14:34 UTC
All submissions hopefully done, openSUSE release inherits from sle12.
Comment 6 Marcus Meissner 2016-03-09 08:09:09 UTC
opensuse 13.2 still missing. (leap gets it from sles12 sp1, yes)

is bsh (no 2) also affected?
Comment 7 Swamp Workflow Management 2016-03-09 11:12:15 UTC
SUSE-SU-2016:0699-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 967593
CVE References: CVE-2016-2510
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    bsh2-2.0-318.1
Comment 8 Swamp Workflow Management 2016-03-09 11:12:41 UTC
SUSE-SU-2016:0700-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 967593
CVE References: CVE-2016-2510
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    bsh2-2.0.0.b5-3.2
SUSE Linux Enterprise Software Development Kit 12 (src):    bsh2-2.0.0.b5-3.2
Comment 9 Tomáš Chvátal 2016-03-10 09:44:00 UTC
(In reply to Marcus Meissner from comment #6)
> opensuse 13.2 still missing. (leap gets it from sles12 sp1, yes)
>
Will ammend, missed that :)
 
> is bsh (no 2) also affected?

No idea the codebase is completely different, if nothing depends on bsh we could even remove it?
Comment 10 Bernhard Wiedemann 2016-03-10 10:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (967593) was mentioned in
https://build.opensuse.org/request/show/369492 13.2 / bsh2
Comment 11 Marcus Meissner 2016-03-16 15:23:57 UTC
i think we got all submissions.

i dont care much about bsh, you can drop it from factory I think if its not needed
Comment 12 Swamp Workflow Management 2016-03-16 18:12:22 UTC
openSUSE-SU-2016:0788-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 967593
CVE References: CVE-2016-2510
Sources used:
openSUSE Leap 42.1 (src):    bsh2-2.0.0.b5-30.1
Comment 13 Swamp Workflow Management 2016-03-19 15:12:28 UTC
openSUSE-SU-2016:0833-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 967593
CVE References: CVE-2016-2510
Sources used:
openSUSE 13.2 (src):    bsh2-2.0.0.b6-27.3.1