Arbitrary Code Injection Affecting hsqldb package, versions <1.8.0.9-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
14.28% (97th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-HSQLDB-519636
  • published6 Dec 2007
  • disclosed6 Dec 2007

Introduced: 6 Dec 2007

CVE-2007-4575  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade Debian:11 hsqldb to version 1.8.0.9-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream hsqldb package and not the hsqldb package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

References

CVSS Base Scores

version 3.1