USN-6281-1: Velocity Engine vulnerability
Alvaro Munoz discovered that Velocity Engine incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Velocity Engine vulnerability?
The vulnerability ID is USN-6281-1.
What is the impact of this Velocity Engine vulnerability?
If exploited, this vulnerability could allow an attacker to execute arbitrary code.
How can this Velocity Engine vulnerability be exploited?
An attacker can trick a user or an automated system into opening a specially crafted input file.
What is the affected software for this Velocity Engine vulnerability?
The affected software includes Ubuntu with Velocity package versions 1.7-5+deb9u1build0.20.04.1, 1.7-5ubuntu0.18.04.1~esm1, and 1.7-4ubuntu0.1~esm1.
How can I fix this Velocity Engine vulnerability?
To fix this vulnerability, update the Velocity package to version 1.7-5+deb9u1build0.20.04.1, 1.7-5ubuntu0.18.04.1~esm1, or 1.7-4ubuntu0.1~esm1 depending on your Ubuntu version.