RHSA-2023:0005: Important: bcel security update
The Byte Code Engineering Library (Apache Commons BCEL) is intended to give users a convenient way to analyze, create, and manipulate (binary) Java class files (those ending with .class).Security Fix(es): Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing (CVE-2022-42920) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bcelto a version that resolves this vulnerability.Fixed in 6.4.1-9.el9_1 - Upgrade
Upgrade
bcelto a version that resolves this vulnerability.Fixed in 6.4.1-9.el9_1 - Upgrade
Upgrade
bcel-6.4.1-9.el9_1.noarch.rpmto a version that resolves this vulnerability.Fixed in 6.4.1-9.el9_1 - Upgrade
Upgrade
bcel-6.4.1-9.el9_1.src.rpmto a version that resolves this vulnerability.Fixed in 6.4.1-9.el9_1
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0005?
The severity of RHSA-2023:0005 is classified as important.
How do I fix RHSA-2023:0005?
To fix RHSA-2023:0005, update the bcel package to version 6.4.1-9.el9_1 or later.
What vulnerability is addressed in RHSA-2023:0005?
RHSA-2023:0005 addresses a vulnerability in the Byte Code Engineering Library (Apache Commons BCEL) related to arbitrary bytecode execution.
Which software is affected by RHSA-2023:0005?
RHSA-2023:0005 affects the bcel package version prior to 6.4.1-9.el9_1.
What type of attack does RHSA-2023:0005 help mitigate?
RHSA-2023:0005 helps mitigate the risk of executing malicious or arbitrary bytecode through out-of-bounds inputs.