HSQLDB is vulnerable to remote code execution. The static methods of all available Java classes can be accessed as functions using crafted database documents when the system property hsqldb.method_class_names
is not set. A remote attacker is able to exploit the vulnerability to execute arbitrary Java code.
bugs.gentoo.org/show_bug.cgi?id=200771
bugs.gentoo.org/show_bug.cgi?id=201799
lists.opensuse.org/opensuse-security-announce/2007-12/msg00005.html
secunia.com/advisories/27914
secunia.com/advisories/27916
secunia.com/advisories/27928
secunia.com/advisories/27931
secunia.com/advisories/27972
secunia.com/advisories/28018
secunia.com/advisories/28039
secunia.com/advisories/28286
secunia.com/advisories/28585
secunia.com/advisories/30100
sunsolve.sun.com/search/document.do?assetkey=1-26-103141-1
sunsolve.sun.com/search/document.do?assetkey=1-66-200637-1
www.debian.org/security/2007/dsa-1419
www.gentoo.org/security/en/glsa/glsa-200712-25.xml
www.mandriva.com/security/advisories?name=MDVSA-2008:095
www.openoffice.org/security/cves/CVE-2007-4575.html
www.redhat.com/archives/fedora-package-announce/2007-December/msg00134.html
www.redhat.com/archives/fedora-package-announce/2007-December/msg00155.html
www.redhat.com/archives/fedora-package-announce/2007-December/msg00281.html
www.redhat.com/support/errata/RHSA-2007-1048.html
www.redhat.com/support/errata/RHSA-2007-1090.html
www.redhat.com/support/errata/RHSA-2008-0151.html
www.redhat.com/support/errata/RHSA-2008-0158.html
www.redhat.com/support/errata/RHSA-2008-0213.html
www.securityfocus.com/bid/26703
www.securitytracker.com/id?1019041
www.ubuntu.com/usn/usn-609-1
www.vupen.com/english/advisories/2007/4092
www.vupen.com/english/advisories/2007/4146
bugs.gentoo.org/200771
bugs.gentoo.org/201799
exchange.xforce.ibmcloud.com/vulnerabilities/38882
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10153
sourceforge.net/p/hsqldb/svn/2750/tree//base-one/trunk/src/org/hsqldb/Database.java?diff=52dbf3432718462d0dafa6ee:2749
sourceforge.net/p/hsqldb/svn/2750/tree//base-one/trunk/src/org/hsqldb/persist/HsqlDatabaseProperties.java?diff=52dbf3432718462d0dafa6ee:2749
sourceforge.net/p/hsqldb/svn/2752/tree//base-one/trunk/src/org/hsqldb/persist/HsqlDatabaseProperties.java?diff=52dbf3432718462d0dafa6ee:2751
www.redhat.com/archives/fedora-package-announce/2008-January/msg00678.html
www.redhat.com/archives/fedora-package-announce/2008-January/msg00753.html