First published: Wed Jun 08 2011(Updated: )
The xerces-j2 packages provide the Apache Xerces2 Java Parser, a<br>high-performance XML parser. A Document Type Definition (DTD) defines the<br>legal syntax (and also which elements can be used) for certain types of<br>files, such as XML files.<br>A flaw was found in the way the Apache Xerces2 Java Parser processed the<br>SYSTEM identifier in DTDs. A remote attacker could provide a<br>specially-crafted XML file, which once parsed by an application using the<br>Apache Xerces2 Java Parser, would lead to a denial of service (application<br>hang due to excessive CPU use). (CVE-2009-2625)<br>Users should upgrade to these updated packages, which contain a backported<br>patch to correct this issue. Applications using the Apache Xerces2 Java<br>Parser must be restarted for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xerces-j2 | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2 | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-debuginfo | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-demo | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-apis | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-impl | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-other | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-xni | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-scripts | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-debuginfo | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-demo | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-apis | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-impl | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-other | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-javadoc-xni | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
redhat/xerces-j2-scripts | <2.7.1-12.6.el6_0 | 2.7.1-12.6.el6_0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.