See also: https://issues.apache.org/jira/browse/XERCESC-2188 https://salsa.debian.org/bblough/xerces-c/-/blob/debian/master/debian/patches/CVE-2018-1311-mitigation.patch At least Debian and RHEL6-7 seem to apply the non-upstream patch, with Fedora seemingly unsure.
Package list is empty or all packages have requested keywords.
There's an apparently leaky fix here: https://issues.apache.org/jira/browse/XERCESC-2188
And there appears to be a better fix here, with a new CVE and advisory: https://github.com/apache/xerces-c/pull/54 https://www.openwall.com/lists/oss-security/2024/02/16/1