Oval Definition:oval:org.opensuse.security:def:58556
Revision Date:2020-12-01Version:1
Title:Security update for xerces-j2 (Moderate)
Description:

xerces-j2 was updated to fix several issues.

This security issue was fixed:

- bsc#814241: Prevent possible DoS through very long attribute names

This non-security issue was fixed:

- Prevent StackOverflowError when applying a pattern restriction on long strings while trying to validate an XML file against a schema (bsc#1047536, bsc#879138)
Family:unixClass:patch
Status:Reference(s):1014702
1014863
1015169
1016779
1017081
1017084
1018808
1019016
1020491
1020589
1020928
1021129
1021195
1021481
1022541
1023004
1023053
1023073
1023907
1024972
1026583
1042910
1047536
1053352
1056127
1056128
1056129
1056131
1056132
1056136
1059554
1085449
1093311
1098998
1103098
1106222
1110910
1111006
1111010
1111013
1114422
1119947
1123823
1123828
1123832
1156323
1156324
1156326
1156328
1156329
1160305
1160498
1162687
1162689
1162691
1173369
1176756
1177872
814241
879138
887877
909695
926974
936032
959495
977027
977410
986630
991464
CVE-2014-4975
CVE-2015-1855
CVE-2015-3900
CVE-2015-7551
CVE-2016-10028
CVE-2016-10029
CVE-2016-10155
CVE-2016-2339
CVE-2016-6489
CVE-2016-9921
CVE-2016-9922
CVE-2017-12617
CVE-2017-13728
CVE-2017-13729
CVE-2017-13730
CVE-2017-13731
CVE-2017-13732
CVE-2017-13733
CVE-2017-2615
CVE-2017-2620
CVE-2017-5525
CVE-2017-5526
CVE-2017-5552
CVE-2017-5578
CVE-2017-5664
CVE-2017-5667
CVE-2017-5856
CVE-2017-5857
CVE-2017-5898
CVE-2017-7674
CVE-2018-10839
CVE-2018-12359
CVE-2018-12360
CVE-2018-12362
CVE-2018-12363
CVE-2018-12364
CVE-2018-12365
CVE-2018-12366
CVE-2018-12368
CVE-2018-1417
CVE-2018-15746
CVE-2018-16884
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-20748
CVE-2018-20749
CVE-2018-20750
CVE-2018-2783
CVE-2018-2790
CVE-2018-2794
CVE-2018-2795
CVE-2018-2796
CVE-2018-2797
CVE-2018-2798
CVE-2018-2799
CVE-2018-2800
CVE-2018-2814
CVE-2018-5156
CVE-2018-5188
CVE-2018-5391
CVE-2019-12523
CVE-2019-12526
CVE-2019-12528
CVE-2019-17015
CVE-2019-17016
CVE-2019-17017
CVE-2019-17021
CVE-2019-17022
CVE-2019-17024
CVE-2019-17026
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2020-15011
CVE-2020-15683
CVE-2020-15969
CVE-2020-8449
CVE-2020-8450
CVE-2020-8517
SUSE-SU-2017:0625-1
SUSE-SU-2017:1067-1
SUSE-SU-2017:1481-1
SUSE-SU-2017:2744-1
SUSE-SU-2017:3039-1
SUSE-SU-2018:0120-1
SUSE-SU-2018:2322-1
SUSE-SU-2018:4237-1
SUSE-SU-2019:0313-1
SUSE-SU-2020:2048-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND dnsmasq-2.78-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.24.2-lp151.2.3 is installed
  • OR libjavascriptcoregtk-4_0-18-32bit-2.24.2-lp151.2.3 is installed
  • OR libwebkit2gtk-4_0-37-2.24.2-lp151.2.3 is installed
  • OR libwebkit2gtk-4_0-37-32bit-2.24.2-lp151.2.3 is installed
  • OR libwebkit2gtk3-lang-2.24.2-lp151.2.3 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.24.2-lp151.2.3 is installed
  • OR typelib-1_0-WebKit2-4_0-2.24.2-lp151.2.3 is installed
  • OR typelib-1_0-WebKit2WebExtension-4_0-2.24.2-lp151.2.3 is installed
  • OR webkit-jsc-4-2.24.2-lp151.2.3 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.24.2-lp151.2.3 is installed
  • OR webkit2gtk3-2.24.2-lp151.2.3 is installed
  • OR webkit2gtk3-devel-2.24.2-lp151.2.3 is installed
  • OR webkit2gtk3-minibrowser-2.24.2-lp151.2.3 is installed
  • OR webkit2gtk3-plugin-process-gtk2-2.24.2-lp151.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • xerces-j2-2.8.1-268.6 is installed
  • OR xerces-j2-xml-apis-2.8.1-268.6 is installed
  • OR xerces-j2-xml-resolver-2.8.1-268.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • qemu-2.6.2-41.46 is installed
  • OR qemu-block-curl-2.6.2-41.46 is installed
  • OR qemu-block-rbd-2.6.2-41.46 is installed
  • OR qemu-block-ssh-2.6.2-41.46 is installed
  • OR qemu-guest-agent-2.6.2-41.46 is installed
  • OR qemu-ipxe-1.0.0-41.46 is installed
  • OR qemu-kvm-2.6.2-41.46 is installed
  • OR qemu-lang-2.6.2-41.46 is installed
  • OR qemu-seabios-1.9.1-41.46 is installed
  • OR qemu-sgabios-8-41.46 is installed
  • OR qemu-tools-2.6.2-41.46 is installed
  • OR qemu-vgabios-1.9.1-41.46 is installed
  • OR qemu-x86-2.6.2-41.46 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.25-38.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • MozillaFirefox-52.9.0esr-109.38 is installed
  • OR MozillaFirefox-devel-52.9.0esr-109.38 is installed
  • OR MozillaFirefox-translations-52.9.0esr-109.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libasan2-5.3.1+r233831-12 is installed
  • OR libasan2-32bit-5.3.1+r233831-12 is installed
  • OR libffi4-5.3.1+r233831-12 is installed
  • OR libffi4-32bit-5.3.1+r233831-12 is installed
  • OR libmpx0-5.3.1+r233831-12 is installed
  • OR libmpx0-32bit-5.3.1+r233831-12 is installed
  • OR libmpxwrappers0-5.3.1+r233831-12 is installed
  • OR libmpxwrappers0-32bit-5.3.1+r233831-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND ucode-intel-20190618-13.47 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libX11-1.6.2-12.8 is installed
  • OR libX11-6-1.6.2-12.8 is installed
  • OR libX11-6-32bit-1.6.2-12.8 is installed
  • OR libX11-data-1.6.2-12.8 is installed
  • OR libX11-xcb1-1.6.2-12.8 is installed
  • OR libX11-xcb1-32bit-1.6.2-12.8 is installed
  • OR libxcb-1.10-4.5 is installed
  • OR libxcb-dri2-0-1.10-4.5 is installed
  • OR libxcb-dri2-0-32bit-1.10-4.5 is installed
  • OR libxcb-dri3-0-1.10-4.5 is installed
  • OR libxcb-dri3-0-32bit-1.10-4.5 is installed
  • OR libxcb-glx0-1.10-4.5 is installed
  • OR libxcb-glx0-32bit-1.10-4.5 is installed
  • OR libxcb-present0-1.10-4.5 is installed
  • OR libxcb-present0-32bit-1.10-4.5 is installed
  • OR libxcb-randr0-1.10-4.5 is installed
  • OR libxcb-render0-1.10-4.5 is installed
  • OR libxcb-render0-32bit-1.10-4.5 is installed
  • OR libxcb-shape0-1.10-4.5 is installed
  • OR libxcb-shm0-1.10-4.5 is installed
  • OR libxcb-shm0-32bit-1.10-4.5 is installed
  • OR libxcb-sync1-1.10-4.5 is installed
  • OR libxcb-sync1-32bit-1.10-4.5 is installed
  • OR libxcb-xf86dri0-1.10-4.5 is installed
  • OR libxcb-xfixes0-1.10-4.5 is installed
  • OR libxcb-xfixes0-32bit-1.10-4.5 is installed
  • OR libxcb-xinerama0-1.10-4.5 is installed
  • OR libxcb-xkb1-1.10-4.5 is installed
  • OR libxcb-xkb1-32bit-1.10-4.5 is installed
  • OR libxcb-xv0-1.10-4.5 is installed
  • OR libxcb1-1.10-4.5 is installed
  • OR libxcb1-32bit-1.10-4.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • curl-7.37.0-37.43 is installed
  • OR libcurl4-7.37.0-37.43 is installed
  • OR libcurl4-32bit-7.37.0-37.43 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • g3utils-1.1.36-58.3 is installed
  • OR mgetty-1.1.36-58.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libarchive13-3.1.2-25 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • ardana-ansible-8.0+git.1583432621.24fa60e-3.70 is installed
  • OR ardana-barbican-8.0+git.1585152761.8ef3d61-4.33 is installed
  • OR ardana-db-8.0+git.1583944923.03cca6c-3.31 is installed
  • OR ardana-monasca-8.0+git.1583944894.38f023a-3.24 is installed
  • OR ardana-mq-8.0+git.1583944811.dc14403-3.19 is installed
  • OR ardana-neutron-8.0+git.1584715262.e4ea620-3.39 is installed
  • OR ardana-octavia-8.0+git.1585171918.418f5cf-3.26 is installed
  • OR ardana-tempest-8.0+git.1585311051.6ab5488-3.33 is installed
  • OR documentation-suse-openstack-cloud-installation-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-operations-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-opsconsole-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-planning-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-security-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-supplement-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-upstream-admin-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-upstream-user-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-user-8.20200319-1.23 is installed
  • OR memcached-1.5.17-3.3 is installed
  • OR openstack-manila-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-api-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-data-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-doc-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-scheduler-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-share-5.1.1~dev5-3.26 is installed
  • OR openstack-neutron-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-dhcp-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-doc-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-ha-tool-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-l3-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-linuxbridge-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-macvtap-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-metadata-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-metering-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-openvswitch-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-server-11.0.9~dev63-3.30 is installed
  • OR openstack-nova-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-api-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-cells-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-compute-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-conductor-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-console-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-consoleauth-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-doc-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-novncproxy-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-placement-api-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-scheduler-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-serialproxy-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-vncproxy-16.1.9~dev61-3.35 is installed
  • OR pdns-4.1.2-3.6 is installed
  • OR pdns-backend-mysql-4.1.2-3.6 is installed
  • OR python-amqp-2.4.2-3.9 is installed
  • OR python-manila-5.1.1~dev5-3.26 is installed
  • OR python-neutron-11.0.9~dev63-3.30 is installed
  • OR python-nova-16.1.9~dev61-3.35 is installed
  • OR venv-openstack-aodh-5.1.1~dev7-12.24 is installed
  • OR venv-openstack-aodh-x86_64-5.1.1~dev7-12.24 is installed
  • OR venv-openstack-barbican-5.0.2~dev3-12.25 is installed
  • OR venv-openstack-barbican-x86_64-5.0.2~dev3-12.25 is installed
  • OR venv-openstack-ceilometer-9.0.8~dev7-12.22 is installed
  • OR venv-openstack-ceilometer-x86_64-9.0.8~dev7-12.22 is installed
  • OR venv-openstack-cinder-11.2.3~dev23-14.25 is installed
  • OR venv-openstack-cinder-x86_64-11.2.3~dev23-14.25 is installed
  • OR venv-openstack-designate-5.0.3~dev7-12.23 is installed
  • OR venv-openstack-designate-x86_64-5.0.3~dev7-12.23 is installed
  • OR venv-openstack-freezer-5.0.0.0~xrc2~dev2-10.20 is installed
  • OR venv-openstack-freezer-x86_64-5.0.0.0~xrc2~dev2-10.20 is installed
  • OR venv-openstack-glance-15.0.3~dev3-12.23 is installed
  • OR venv-openstack-glance-x86_64-15.0.3~dev3-12.23 is installed
  • OR venv-openstack-heat-9.0.8~dev22-12.25 is installed
  • OR venv-openstack-heat-x86_64-9.0.8~dev22-12.25 is installed
  • OR venv-openstack-ironic-9.1.8~dev8-12.25 is installed
  • OR venv-openstack-ironic-x86_64-9.1.8~dev8-12.25 is installed
  • OR venv-openstack-keystone-12.0.4~dev5-11.26 is installed
  • OR venv-openstack-keystone-x86_64-12.0.4~dev5-11.26 is installed
  • OR venv-openstack-magnum-5.0.2_5.0.2_5.0.2~dev31-11.24 is installed
  • OR venv-openstack-magnum-x86_64-5.0.2_5.0.2_5.0.2~dev31-11.24 is installed
  • OR venv-openstack-manila-5.1.1~dev5-12.29 is installed
  • OR venv-openstack-manila-x86_64-5.1.1~dev5-12.29 is installed
  • OR venv-openstack-monasca-ceilometer-1.5.1_1.5.1_1.5.1~dev3-8.20 is installed
  • OR venv-openstack-monasca-ceilometer-x86_64-1.5.1_1.5.1_1.5.1~dev3-8.20 is installed
  • OR venv-openstack-murano-4.0.2~dev2-12.20 is installed
  • OR venv-openstack-murano-x86_64-4.0.2~dev2-12.20 is installed
  • OR venv-openstack-neutron-11.0.9~dev63-13.28 is installed
  • OR venv-openstack-neutron-x86_64-11.0.9~dev63-13.28 is installed
  • OR venv-openstack-nova-16.1.9~dev61-11.26 is installed
  • OR venv-openstack-nova-x86_64-16.1.9~dev61-11.26 is installed
  • OR venv-openstack-octavia-1.0.6~dev3-12.25 is installed
  • OR venv-openstack-octavia-x86_64-1.0.6~dev3-12.25 is installed
  • OR venv-openstack-sahara-7.0.5~dev4-11.24 is installed
  • OR venv-openstack-sahara-x86_64-7.0.5~dev4-11.24 is installed
  • OR venv-openstack-trove-8.0.2~dev2-11.24 is installed
  • OR venv-openstack-trove-x86_64-8.0.2~dev2-11.24 is installed
  • OR zookeeper-3.4.10-3.6 is installed
  • OR zookeeper-server-3.4.10-3.6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libexif-0.6.22-8.9 is installed
  • OR libexif12-0.6.22-8.9 is installed
  • OR libexif12-32bit-0.6.22-8.9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND nodejs6-6.17.0-11.27 is installed
  • BACK