| Summary: | xalan-j2 new security issue CVE-2014-0107 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | dmorganec, mageia, sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/592272/ | ||
| Whiteboard: | MGA3TOO advisory mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok | ||
| Source RPM: | xalan-j2-2.7.1-5.mga3.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2014-03-27 18:23:51 CET
David Walser
2014-03-27 18:24:02 CET
Whiteboard:
(none) =>
MGA4TOO, MGA3TOO Patched packages uploaded for Mageia 3, Mageia 4, and Cauldron. Note to QA: just testing that these install should be sufficient. Advisory: ======================== Updated xalan-j2 packages fix security vulnerability: Nicolas Gregoire discovered several vulnerabilities in libxalan2-java. Crafted XSLT programs could access system properties or load arbitrary classes, resulting in information disclosure and, potentially, arbitrary code execution (CVE-2014-0107). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0107 https://www.debian.org/security/2014/dsa-2886 ======================== Updated packages in core/updates_testing: ======================== xalan-j2-2.7.1-5.1.mga3 xalan-j2-xsltc-2.7.1-5.1.mga3 xalan-j2-manual-2.7.1-5.1.mga3 xalan-j2-javadoc-2.7.1-5.1.mga3 xalan-j2-demo-2.7.1-5.1.mga3 xalan-j2-2.7.1-6.1.mga4 xalan-j2-xsltc-2.7.1-6.1.mga4 xalan-j2-manual-2.7.1-6.1.mga4 xalan-j2-javadoc-2.7.1-6.1.mga4 xalan-j2-demo-2.7.1-6.1.mga4 from SRPMS: xalan-j2-2.7.1-5.1.mga3.src.rpm xalan-j2-2.7.1-6.1.mga4.src.rpm CC:
(none) =>
dmorganec Testing complete mga3 32 & 64 As with most java stuff, just checking the update installs cleanly, which it does. Whiteboard:
MGA3TOO =>
MGA3TOO mga3-32-ok mga3-64-ok Testing complete mga4 32 & 64 Whiteboard:
MGA3TOO mga3-32-ok mga3-64-ok =>
MGA3TOO mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok Advisory uploaded. Validating. Could sysadmin please push to 3 & 4 updates Thanks Keywords:
(none) =>
validated_update
David Walser
2014-04-02 19:03:28 CEST
Severity:
normal =>
critical http://advisories.mageia.org/MGASA-2014-0152.html Status:
NEW =>
RESOLVED |