Oval Definition:oval:org.mitre.oval:def:23701
Revision Date:2014-05-26Version:13
Title:ELSA-2011:0858: xerces-j2 security update (Moderate)
Description:XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-2625
ELSA-2011:0858-01
Platform(s):Oracle Linux 6
Product(s):xerces-j2
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2 is earlier than 0:2.7.1-12.6.el6_0
  • OR xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0
  • BACK