Oval Definition:oval:com.redhat.rhsa:def:20141319
Revision Date:2014-09-29Version:636
Title:RHSA-2014:1319: xerces-j2 security update (Moderate)
Description:Apache Xerces for Java (Xerces-J) is a high performance, standards compliant, validating XML parser written in Java. The xerces-j2 packages provide Xerces-J version 2.

  • A resource consumption issue was found in the way Xerces-J handled XML declarations. A remote attacker could use an XML document with a specially crafted declaration using a long pseudo-attribute name that, when parsed by an application using Xerces-J, would cause that application to use an excessive amount of CPU. (CVE-2013-4002)

    All xerces-j2 users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. Applications using the Xerces-J must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4002
    CVE-2013-4002
    RHSA-2014:1319
    RHSA-2014:1319-00
    RHSA-2014:1319-01
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • xerces-j2 is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2 is signed with Red Hat redhatrelease2 key
  • xerces-j2-demo is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-demo is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-javadoc-apis is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-javadoc-impl is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-other is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-javadoc-other is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-javadoc-xni is signed with Red Hat redhatrelease2 key
  • xerces-j2-scripts is earlier than 0:2.7.1-12.7.el6_5
  • AND xerces-j2-scripts is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • xerces-j2 is earlier than 0:2.11.0-17.el7_0
  • AND xerces-j2 is signed with Red Hat redhatrelease2 key
  • xerces-j2-demo is earlier than 0:2.11.0-17.el7_0
  • AND xerces-j2-demo is signed with Red Hat redhatrelease2 key
  • xerces-j2-javadoc is earlier than 0:2.11.0-17.el7_0
  • AND xerces-j2-javadoc is signed with Red Hat redhatrelease2 key
  • BACK