Oval Definition:oval:com.ubuntu.precise:def:20140107000
Revision Date:2014-04-15Version:1
Title:CVE-2014-0107 on Ubuntu 12.04 LTS (precise) - medium.
Description:The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-0107
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'libxalan2-java' package in precise was vulnerable but has been fixed (note: '2.7.1-7ubuntu0.1').
  • BACK