First published: Mon Nov 30 2009(Updated: )
The xerces-j2 packages provide the Apache Xerces2 Java Parser, a<br>high-performance XML parser. A Document Type Definition (DTD) defines the<br>legal syntax (and also which elements can be used) for certain types of<br>files, such as XML files.<br>A flaw was found in the way the Apache Xerces2 Java Parser processed the<br>SYSTEM identifier in DTDs. A remote attacker could provide a<br>specially-crafted XML file, which once parsed by an application using the<br>Apache Xerces2 Java Parser, would lead to a denial of service (application<br>hang due to excessive CPU use). (CVE-2009-2625)<br>Users should upgrade to these updated packages, which contain a backported<br>patch to correct this issue. Applications using the Apache Xerces2 Java<br>Parser must be restarted for this update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xerces-j2 | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2 | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-demo | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-apis | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-impl | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-other | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-xni | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-scripts | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-demo | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-apis | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-impl | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-other | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-javadoc-xni | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
redhat/xerces-j2-scripts | <2.7.1-7jpp.2.el5_4.2 | 2.7.1-7jpp.2.el5_4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:1615 is classified as moderate.
To fix RHSA-2009:1615, upgrade the xerces-j2 packages to version 2.7.1-7jpp.2.el5_4.2.
The affected packages for RHSA-2009:1615 include xerces-j2, xerces-j2-demo, and several javadoc-related packages.
No, RHSA-2009:1615 is not a critical vulnerability; it is rated as moderate in severity.
RHSA-2009:1615 pertains to a flaw found in the way the Apache Xerces2 Java Parser processes XML documents.