MGASA-2015-0211
Dashboard / Vulnerabilities / MGASA-2015-0211
Summary: Updated springframework packages fix CVE-2014-0225
Details: Updated springframework packages fix security vulnerabilities: When processing user provided XML documents, the Spring Framework did not disable by default the resolution of URI references in a DTD declaration. By observing differences in response times, an attacker could then identify valid IP addresses on the internal network with functioning web servers (CVE-2014-0225).
References: https://advisories.mageia.org/MGASA-2015-0211.html, https://bugs.mageia.org/show_bug.cgi?id=15886, https://lists.fedoraproject.org/pipermail/package-announce/2015-May/157348.html
Affected packages
Package
Name: springframework
Purl: pkg:rpm/mageia/springframework?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
