SCIENTIFIC-LINUX-ERRATA Archives

April 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 1 Apr 2014 19:33:53 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (42 lines)
Synopsis:          Important: xalan-j2 security update
Advisory ID:       SLSA-2014:0348-1
Issue Date:        2014-04-01
CVE Numbers:       CVE-2014-0107
--

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features. A
remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses Xalan-
Java. (CVE-2014-0107)
--

SL5
  x86_64
    xalan-j2-2.7.0-6jpp.2.x86_64.rpm
    xalan-j2-debuginfo-2.7.0-6jpp.2.x86_64.rpm
    xalan-j2-manual-2.7.0-6jpp.2.x86_64.rpm
    xalan-j2-xsltc-2.7.0-6jpp.2.x86_64.rpm
    xalan-j2-demo-2.7.0-6jpp.2.x86_64.rpm
    xalan-j2-javadoc-2.7.0-6jpp.2.x86_64.rpm
  i386
    xalan-j2-2.7.0-6jpp.2.i386.rpm
    xalan-j2-debuginfo-2.7.0-6jpp.2.i386.rpm
    xalan-j2-manual-2.7.0-6jpp.2.i386.rpm
    xalan-j2-xsltc-2.7.0-6jpp.2.i386.rpm
    xalan-j2-demo-2.7.0-6jpp.2.i386.rpm
    xalan-j2-javadoc-2.7.0-6jpp.2.i386.rpm
SL6
  noarch
    xalan-j2-2.7.0-9.9.el6_5.noarch.rpm
    xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm
    xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm
    xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm
    xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2