Summary: | <dev-java/xalan-2.7.2: insufficient constraints in secure processing feature (CVE-2014-0107) (oCERT-2014-002) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | java |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1080248 | ||
Whiteboard: | B2 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Upstream bug: https://issues.apache.org/jira/browse/XALANJ-2435 Upstream patch commit: http://svn.apache.org/viewvc?view=revision&revision=1581058 External References: http://www.ocert.org/advisories/ocert-2014-002.html CVE-2014-0107 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0107): The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function. Note as per upstream this has been Fixed in 2.7.2 Also has been pushed to: https://svn.apache.org/repos/asf/xalan/java/branches/xalan-j_2_7_1_maint Maintainer(s): after the bump please let us know when the ebuild is ready for stabilization. dev-java/xalan-serializer and dev-java/xalan now bumped. Removal may have to wait till I drop ia64. This is next on my list but I'm about to leave for a week. I have marked these stable according to ALLARCHES policy and dropped the old versions. Security team, please proceed. ping @security. Please proceed and close this bug if there's no outstanding item left. GLSA Assigned: 322528253 This issue was resolved and addressed in GLSA 201604-02 at https://security.gentoo.org/glsa/201604-02 by GLSA coordinator Yury German (BlueKnight). |