17 karma · joined April 10, 2013
"So replacing your installations with a hardened version of Apache Commons Collections will not make your application resist this vulnerability."
The core problem really stems from the idea that OO models encapsulate data and behaviors. Behaviors mean code execution - so, anything that will deserialize objects is giving the person who serialized them the ability to control the execution flow. If this is a listener on the network, than things are really bad :-)
So, it's great that a set of gadgets have been removed, it's neat to see the application of resources to make that happen. I have to agree with Ben, that any system that relies on object serialization from untrusted sources (in any language) is still vulnerable, it just might require a more specific gadget chain. Too many vendors have fixed their products by just updating the library and not removing the dependency on dangerous object deserailization.
Something that is called out in the Java secure coding guidelines:
http://www.oracle.com/technetwork/java/seccodeguide-139067.h...
and is something that goes way back in many languages. It seems to be a vuln pattern that keeps getting repeated sadly.
http://articles.baltimoresun.com/1996-05-18/business/1996139...