XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
History
                    23 May 2025, 17:54
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_middleware:1:*:*:*:*:*:*:* | |
| First Time | Redhat Redhat fuse Xstream Redhat jboss Middleware Xstream xstream | |
| References | () http://www.debian.org/security/2017/dsa-3841 - Third Party Advisory, Mailing List | |
| References | () http://www.securityfocus.com/bid/100687 - Third Party Advisory, VDB Entry, Broken Link | |
| References | () http://www.securitytracker.com/id/1039499 - Third Party Advisory, VDB Entry, Broken Link | |
| References | () https://www-prd-trops.events.ibm.com/node/715749 - Permissions Required, Broken Link | 
21 Nov 2024, 03:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.debian.org/security/2017/dsa-3841 - Third Party Advisory | |
| References | () http://www.securityfocus.com/bid/100687 - Third Party Advisory, VDB Entry | |
| References | () http://www.securitytracker.com/id/1039499 - Third Party Advisory, VDB Entry | |
| References | () http://x-stream.github.io/CVE-2017-7957.html - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2017:1832 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2017:2888 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2017:2889 - Third Party Advisory | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/125800 - Third Party Advisory, VDB Entry | |
| References | () https://www-prd-trops.events.ibm.com/node/715749 - Permissions Required | 
Information
                Published : 2017-04-29 19:59
Updated : 2025-05-23 17:54
NVD link : CVE-2017-7957
Mitre link : CVE-2017-7957
CVE.ORG link : CVE-2017-7957
JSON object : View
Products Affected
                xstream
- xstream
redhat
- jboss_middleware
- fuse
debian
- debian_linux
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
