Oval Definition:oval:com.redhat.rhsa:def:20091615
Revision Date:2009-11-30Version:646
Title:RHSA-2009:1615: xerces-j2 security update (Moderate)
Description:The xerces-j2 packages provide the Apache Xerces2 Java Parser, a high-performance XML parser. A Document Type Definition (DTD) defines the legal syntax (and also which elements can be used) for certain types of files, such as XML files.

  • A flaw was found in the way the Apache Xerces2 Java Parser processed the SYSTEM identifier in DTDs. A remote attacker could provide a specially-crafted XML file, which once parsed by an application using the Apache Xerces2 Java Parser, would lead to a denial of service (application hang due to excessive CPU use). (CVE-2009-2625)

    Users should upgrade to these updated packages, which contain a backported patch to correct this issue. Applications using the Apache Xerces2 Java Parser must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2625
    RHSA-2009:1615
    RHSA-2009:1615-01
    RHSA-2009:1615-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2 is signed with Red Hat redhatrelease2 key
  • xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-demo is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-javadoc-apis is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-javadoc-impl is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-javadoc-other is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-javadoc-xni is signed with Red Hat redhatrelease2 key
  • xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2
  • AND xerces-j2-scripts is signed with Red Hat redhatrelease2 key
  • BACK