UbuntuUpdates.org

Package "solr-common"

Name: solr-common

Description:

Enterprise search server based on Lucene3 - common files

Latest version: 3.6.2+dfsg-8ubuntu0.1
Release: xenial (16.04)
Level: updates
Repository: universe
Head package: lucene-solr
Homepage: http://lucene.apache.org

Links


Download "solr-common"


Other versions of "solr-common" in Xenial

Repository Area Version
base universe 3.6.2+dfsg-8
security universe 3.6.2+dfsg-8ubuntu0.1

Changelog

Version: 3.6.2+dfsg-8ubuntu0.1 2020-01-29 18:06:27 UTC

  lucene-solr (3.6.2+dfsg-8ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: Remote code execution via an XXE
    - debian/patches/CVE-2017-12629-1.patch: SOLR-11477: Disallow resolving of
      external entities in Lucene queryparser/xml/CoreParser
    - debian/patches/CVE-2017-12629-2.patch: RunExecutableListener was removed
      for security reasons
    - CVE-2017-12629

 -- Mike Salvatore <email address hidden> Tue, 28 Jan 2020 09:00:46 -0500

CVE-2017-12629 Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li



About   -   Send Feedback to @ubuntu_updates