Oval Definition:oval:com.redhat.rhsa:def:20110858
Revision Date:2011-06-08Version:635
Title:RHSA-2011:0858: xerces-j2 security update (Moderate)
Description:The xerces-j2 packages provide the Apache Xerces2 Java Parser, a high-performance XML parser. A Document Type Definition (DTD) defines the legal syntax (and also which elements can be used) for certain types of files, such as XML files.

  • A flaw was found in the way the Apache Xerces2 Java Parser processed the SYSTEM identifier in DTDs. A remote attacker could provide a specially-crafted XML file, which once parsed by an application using the Apache Xerces2 Java Parser, would lead to a denial of service (application hang due to excessive CPU use). (CVE-2009-2625)

    Users should upgrade to these updated packages, which contain a backported patch to correct this issue. Applications using the Apache Xerces2 Java Parser must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2625
    CVE-2009-2625
    RHSA-2011:0858
    RHSA-2011:0858-01
    RHSA-2011:0858-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • xerces-j2 is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2 is signed with Red Hat redhatrelease2 key
  • xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-demo is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-javadoc-apis is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-javadoc-impl is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-javadoc-other is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-javadoc-xni is signed with Red Hat redhatrelease2 key
  • xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0
  • AND xerces-j2-scripts is signed with Red Hat redhatrelease2 key
  • BACK