ELA-707-1 bcel security update

arbitrary code execution

2022-10-18
Packagebcel
Version6.0~rc3-1+deb8u1 (jessie), 6.0-1+deb9u1 (stretch)
Related CVEs CVE-2022-34169


The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. In Debian the vulnerable code is in the bcel source package.



For Debian 8 jessie, these problems have been fixed in version 6.0~rc3-1+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 6.0-1+deb9u1.

We recommend that you upgrade your bcel packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.