USN-7208-1: Apache Commons BCEL vulnerability
Published Jan 16, 2025
·Updated
Felix Wilhelm discovered that Apache Commons BCEL APIs incorrectly handled parameters due to a memory issue. An attacker supplying malicious input could exploit this to generate and execute arbitrary bytecode.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/libbcel-java<6.5.0-1ubuntu0.1
6.5.0-1ubuntu0.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libbcel-java<6.4.1-1ubuntu0.1~esm1
6.4.1-1ubuntu0.1~esm1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libbcel-java<6.2-1ubuntu0.1~esm1
6.2-1ubuntu0.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libbcel-java<6.0~rc3-2ubuntu1+esm1
6.0~rc3-2ubuntu1+esm1
Ubuntu Ubuntu=16.04
Event History
Jan 16, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7208-1?
The severity of USN-7208-1 is classified as high due to the potential for arbitrary bytecode execution.
2
How do I fix USN-7208-1?
To fix USN-7208-1, update the libbcel-java package to the latest version available for your Ubuntu release.
3
Which Ubuntu versions are affected by USN-7208-1?
USN-7208-1 affects Ubuntu versions 16.04, 18.04, 20.04, and 22.04 with specific libbcel-java package versions.
4
What types of attacks can exploit USN-7208-1?
An attacker can exploit USN-7208-1 by supplying malicious input to trigger the vulnerability and execute arbitrary bytecode.
5
Who discovered the USN-7208-1 vulnerability?
The USN-7208-1 vulnerability was discovered by Felix Wilhelm.