Package: libxalan2-java / 2.7.1-9
Metadata
Package | Version | Patches format |
---|---|---|
libxalan2-java | 2.7.1-9 | 3.0 (quilt) |
Patch series
view the series filePatch | File delta | Description |
---|---|---|
build.patch | (download) |
build.xml |
41 32 + 9 - 0 ! |
--- |
CVE 2014 0107.patch | (download) |
src/org/apache/xalan/processor/TransformerFactoryImpl.java |
4 4 + 0 - 0 ! |
fix for cve-2014-0107: strengthen the secure processing mode by disabling external general entities, foreign attributes and access to the system properties. This could be exploited to execute arbitrary code remotely. |
1