Debian DSA-5004-1 : libxstream-java - security update

critical Nessus Plugin ID 155294

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 10 / 11 host has a package installed that is affected by multiple vulnerabilities as referenced in the dsa-5004 advisory.

Multiple security vulnerabilities have been discovered in XStream, a Java library to serialize objects to XML and back again. These vulnerabilities may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. XStream itself sets up a whitelist by default now, i.e. it blocks all classes except those types it has explicit converters for. It used to have a blacklist by default, i.e. it tried to block all currently known critical classes of the Java runtime.
Main reason for the blacklist were compatibility, it allowed to use newer versions of XStream as drop-in replacement. However, this approach has failed. A growing list of security reports has proven, that a blacklist is inherently unsafe, apart from the fact that types of 3rd libraries were not even considered.
A blacklist scenario should be avoided in general, because it provides a false sense of security. For the oldstable distribution (buster), these problems have been fixed in version 1.4.11.1-1+deb10u3. For the stable distribution (bullseye), these problems have been fixed in version 1.4.15-3+deb11u1. We recommend that you upgrade your libxstream-java packages. For the detailed security status of libxstream-java please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxstream-java

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libxstream-java packages.

For the stable distribution (bullseye), these problems have been fixed in version 1.4.15-3+deb11u1.

See Also

http://www.nessus.org/u?b2068716

https://www.debian.org/security/2021/dsa-5004

https://security-tracker.debian.org/tracker/CVE-2021-21341

https://security-tracker.debian.org/tracker/CVE-2021-21342

https://security-tracker.debian.org/tracker/CVE-2021-21343

https://security-tracker.debian.org/tracker/CVE-2021-21344

https://security-tracker.debian.org/tracker/CVE-2021-21345

https://security-tracker.debian.org/tracker/CVE-2021-21346

https://security-tracker.debian.org/tracker/CVE-2021-21347

https://security-tracker.debian.org/tracker/CVE-2021-21348

https://security-tracker.debian.org/tracker/CVE-2021-21349

https://security-tracker.debian.org/tracker/CVE-2021-21350

https://security-tracker.debian.org/tracker/CVE-2021-21351

https://security-tracker.debian.org/tracker/CVE-2021-29505

https://security-tracker.debian.org/tracker/CVE-2021-39139

https://security-tracker.debian.org/tracker/CVE-2021-39140

https://security-tracker.debian.org/tracker/CVE-2021-39141

https://security-tracker.debian.org/tracker/CVE-2021-39144

https://security-tracker.debian.org/tracker/CVE-2021-39145

https://security-tracker.debian.org/tracker/CVE-2021-39146

https://security-tracker.debian.org/tracker/CVE-2021-39147

https://security-tracker.debian.org/tracker/CVE-2021-39148

https://security-tracker.debian.org/tracker/CVE-2021-39149

https://security-tracker.debian.org/tracker/CVE-2021-39150

https://security-tracker.debian.org/tracker/CVE-2021-39151

https://security-tracker.debian.org/tracker/CVE-2021-39152

https://security-tracker.debian.org/tracker/CVE-2021-39153

https://security-tracker.debian.org/tracker/CVE-2021-39154

https://packages.debian.org/source/buster/libxstream-java

https://packages.debian.org/source/bullseye/libxstream-java

Plugin Details

Severity: Critical

ID: 155294

File Name: debian_DSA-5004.nasl

Version: 1.8

Type: local

Agent: unix

Published: 11/12/2021

Updated: 1/24/2025

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-21350

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2021-21345

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libxstream-java, cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:10.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/10/2021

Vulnerability Publication Date: 3/23/2021

CISA Known Exploited Vulnerability Due Dates: 3/31/2023

Exploitable With

Core Impact

Metasploit (VMware NSX Manager XStream unauthenticated RCE)

Reference Information

CVE: CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351, CVE-2021-29505, CVE-2021-39139, CVE-2021-39140, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145, CVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154