{"id":"MGASA-2016-0164","summary":"Updated xstream packages fix CVE-2016-3674","details":"Updated xstream packages fix security vulnerability:\n\nXStream (x-stream.github.io) is a Java library to marshal Java objects into XML\nand back. For this purpose it supports a lot of different XML parsers. Some of\nthose can also process external entities which was enabled by default. An\nattacker could therefore provide manipulated XML as input to access data on the\nfile system (CVE-2016-3674).\n","modified":"2026-04-16T01:47:50.451899060Z","published":"2016-05-05T16:26:44Z","upstream":["CVE-2016-3674"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0164.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18277"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html"}],"affected":[{"package":{"name":"xstream","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/xstream?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.9-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0164.json"}},{"package":{"name":"javapackages-tools","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/javapackages-tools?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.0-15.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0164.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}