First published: Mon Sep 29 2014(Updated: )
Apache Xerces for Java (Xerces-J) is a high performance, standards<br>compliant, validating XML parser written in Java. The xerces-j2 packages<br>provide Xerces-J version 2.<br>A resource consumption issue was found in the way Xerces-J handled XML<br>declarations. A remote attacker could use an XML document with a specially<br>crafted declaration using a long pseudo-attribute name that, when parsed by<br>an application using Xerces-J, would cause that application to use an<br>excessive amount of CPU. (CVE-2013-4002)<br>All xerces-j2 users are advised to upgrade to these updated packages, which<br>contain a backported patch to correct this issue. Applications using the<br>Xerces-J must be restarted for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xerces-j2 | <2.11.0-17.el7_0 | 2.11.0-17.el7_0 |
redhat/xerces-j2 | <2.11.0-17.el7_0 | 2.11.0-17.el7_0 |
redhat/xerces-j2-demo | <2.11.0-17.el7_0 | 2.11.0-17.el7_0 |
redhat/xerces-j2-javadoc | <2.11.0-17.el7_0 | 2.11.0-17.el7_0 |
redhat/xerces-j2 | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2 | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-debuginfo | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-demo | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-apis | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-impl | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-other | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-xni | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-scripts | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-debuginfo | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-demo | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-apis | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-impl | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-other | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-javadoc-xni | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
redhat/xerces-j2-scripts | <2.7.1-12.7.el6_5 | 2.7.1-12.7.el6_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.