Package: libxalan2-java / 2.7.1-7+deb7u1
Metadata
| Package | Version | Patches format |
|---|---|---|
| libxalan2-java | 2.7.1-7+deb7u1 | 3.0 (quilt) |
Patch series
view the series file| Patch | File delta | Description |
|---|---|---|
| build.patch | (download) |
build.xml |
41 32 + 9 - 0 ! |
--- |
| CVE 2014 0107.patch | (download) |
src/org/apache/xalan/processor/TransformerFactoryImpl.java |
4 4 + 0 - 0 ! |
fix for cve-2014-0107: strengthen the secure processing mode by disabling external general entities, foreign attributes and access to the system properties. This could be exploited to execute arbitrary code remotely. |
1
