diff --git a/SOURCES/CVE-2019-14379.patch b/SOURCES/CVE-2019-14379.patch new file mode 100644 index 0000000..54266c1 --- /dev/null +++ b/SOURCES/CVE-2019-14379.patch @@ -0,0 +1,15 @@ +--- jackson-databind-jackson-databind-2.7.6/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java.orig 2019-09-05 10:22:43.429446495 +0200 ++++ jackson-databind-jackson-databind-2.7.6/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java 2019-09-05 10:33:48.325482004 +0200 +@@ -76,6 +76,12 @@ + // [databind#2334] (2.9.9.1): logback-core + s.add("ch.qos.logback.core.db.DriverManagerConnectionSource"); + ++ // [databind#2387]: EHCache ++ s.add("net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup"); ++ ++ // [databind#2389]: logback/jndi ++ s.add("ch.qos.logback.core.db.JNDIConnectionSource"); ++ + DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); + } + diff --git a/SPECS/jackson-databind.spec b/SPECS/jackson-databind.spec index c9746b9..c162ca1 100644 --- a/SPECS/jackson-databind.spec +++ b/SPECS/jackson-databind.spec @@ -3,7 +3,7 @@ Name: %{?scl_prefix}jackson-databind Version: 2.7.6 -Release: 2.6%{?dist} +Release: 2.7%{?dist} Summary: General data-binding package for Jackson (2.x) License: ASL 2.0 and LGPLv2+ URL: http://wiki.fasterxml.com/JacksonHome @@ -23,6 +23,7 @@ Patch11: CVE-2018-19360.patch Patch12: CVE-2018-19361.patch Patch13: CVE-2018-19362.patch Patch14: CVE-2019-12384.patch +Patch15: CVE-2019-14379.patch BuildRequires: %{?scl_prefix}maven-local BuildRequires: %{?scl_prefix}mvn(com.fasterxml.jackson:jackson-parent:pom:) @@ -62,6 +63,7 @@ This package contains javadoc for %{pkg_name}. %patch12 -p1 %patch13 -p1 %patch14 -p1 +%patch15 -p1 cp -p src/main/resources/META-INF/LICENSE . cp -p src/main/resources/META-INF/NOTICE . @@ -100,6 +102,9 @@ rm src/test/java/com/fasterxml/jackson/databind/ser/TestJdkTypes.java \ %license LICENSE NOTICE %changelog +* Thu Sep 05 2019 Marian Koncek - 2.7.6-2.7 +- Fix CVE-2019-14379 + * Wed Jul 10 2019 Joe Orton - 2.7.6-2.6 - fix CVE-2019-12384