RHSA-2022:8958: Important: bcel security update
The Byte Code Engineering Library (Apache Commons BCEL) is intended to give users a convenient way to analyze, create, and manipulate (binary) Java class files (those ending with .class).Security Fix(es): Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing (CVE-2022-42920) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8958?
The severity of RHSA-2022:8958 is classified as important.
How do I fix RHSA-2022:8958?
To fix RHSA-2022:8958, update the Apache Commons BCEL package to version 5.2-19.el7_9.
What software is affected by RHSA-2022:8958?
RHSA-2022:8958 affects the Apache Commons BCEL package and its related javadoc package.
What type of vulnerability is addressed in RHSA-2022:8958?
RHSA-2022:8958 addresses a vulnerability related to arbitrary bytecode execution due to out-of-bounds access.
Is there a workaround for RHSA-2022:8958?
There are no specific workarounds recommended for RHSA-2022:8958; updating is the best course of action.