Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in dom4j
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in dom4j
ID: FEDORA-2021-f28c870528
Distribution: Fedora
Plattformen: Fedora 34
Datum: Mi, 12. Mai 2021, 08:17
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000632
Applikationen: dom4j

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2021-f28c870528
2021-05-12 05:41:31.252024
-------------------------------------------------------------------------------
-

Name : dom4j
Product : Fedora 34
Version : 2.0.3
Release : 1.fc34
URL : https://dom4j.github.io/
Summary : Open Source XML framework for Java
Description :
dom4j is an Open Source XML framework for Java. dom4j allows you to read,
write, navigate, create and modify XML documents. dom4j integrates with
DOM and SAX and is seamlessly integrated with full XPath support.

-------------------------------------------------------------------------------
-
Update Information:

- Security fix for CVE-2018-1000632 - Update to upstream 2.0.3 bugfix release -
Fix Fedora 34 FTBFS
-------------------------------------------------------------------------------
-
ChangeLog:

* Thu Apr 29 2021 Hans de Goede <hdegoede@redhat.com> - 0:2.0.3-1
- New upstream version 2.0.3
- Fix CVE-2018-1000632 (rhbz#1620535)
* Thu Apr 29 2021 Hans de Goede <hdegoede@redhat.com> - 0:2.0.0-14
- Drop the org.dom4j.datatype bits, these depend on the obsolete msv project
and
no Fedora packages runtime require msv, so no package seem to need these
bits.
- Drop dom4j-demo and dom4j-manual Obsoletes, these no longer exist since F27.
- Fix FTBFS (rhbz#1923601)
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> -
0:2.0.0-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element.
Methods: addElement, addAttribute which can impact the integrity of XML documents
https://bugzilla.redhat.com/show_bug.cgi?id=1620529
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-f28c870528' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung