REDHAT-BUG-2041472: Medium severity OpenJDK JAXP vulnerability
A flaw was found in the way the XMLEntityScanner and XML11EntityScanner classes in the JAXP component of OpenJDK handled and normalized newlines in XML entities. A specially-crafted XML document could cause a Java application to enter an infinite loop when parsed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2041472?
The severity of REDHAT-BUG-2041472 is considered critical due to its potential to cause infinite loops in Java applications.
How do I fix REDHAT-BUG-2041472?
To fix REDHAT-BUG-2041472, you should update OpenJDK to the latest version that includes the security patches for this vulnerability.
What systems are affected by REDHAT-BUG-2041472?
REDHAT-BUG-2041472 affects systems using the JAXP component of OpenJDK, particularly those that handle XML documents.
What type of vulnerability is REDHAT-BUG-2041472?
REDHAT-BUG-2041472 is a parsing vulnerability caused by improper handling of newlines in XML entities.
What impact does REDHAT-BUG-2041472 have on applications?
The impact of REDHAT-BUG-2041472 can lead to unresponsive Java applications due to an infinite loop during XML parsing.