MGASA-2014-0398
Dashboard / Vulnerabilities / MGASA-2014-0398
Summary: Updated xerces-j2 packages fix CVE-2013-4002
Details: Updated xerces-j2 packages fix security vulnerability: A resource consumption issue was found in the way Xerces-J handled XML declarations. A remote attacker could use an XML document with a specially crafted declaration using a long pseudo-attribute name that, when parsed by an application using Xerces-J, would cause that application to use an excessive amount of CPU (CVE-2013-4002).
References: https://advisories.mageia.org/MGASA-2014-0398.html, https://bugs.mageia.org/show_bug.cgi?id=14176, https://rhn.redhat.com/errata/RHSA-2014-1319.html, http://www.mandriva.com/en/support/security/advisories/mbs1/MDVSA-2014%3A193/
Affected packages
Package
Name: xerces-j2
Purl: pkg:rpm/mageia/xerces-j2?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
