The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.
A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)
Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. Applications using the Apache Xerces2 Java
Parser must be restarted for this update to take effect.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 6 | i686 | xerces-j2-debuginfo | < 2.7.1-12.6.el6_0 | xerces-j2-debuginfo-2.7.1-12.6.el6_0.i686.rpm |
RedHat | 6 | ppc64 | xerces-j2-javadoc-other | < 2.7.1-12.6.el6_0 | xerces-j2-javadoc-other-2.7.1-12.6.el6_0.ppc64.rpm |
RedHat | 6 | s390x | xerces-j2-demo | < 2.7.1-12.6.el6_0 | xerces-j2-demo-2.7.1-12.6.el6_0.s390x.rpm |
RedHat | 6 | i686 | xerces-j2-javadoc-xni | < 2.7.1-12.6.el6_0 | xerces-j2-javadoc-xni-2.7.1-12.6.el6_0.i686.rpm |
RedHat | 6 | s390x | xerces-j2-debuginfo | < 2.7.1-12.6.el6_0 | xerces-j2-debuginfo-2.7.1-12.6.el6_0.s390x.rpm |
RedHat | 6 | s390x | xerces-j2 | < 2.7.1-12.6.el6_0 | xerces-j2-2.7.1-12.6.el6_0.s390x.rpm |
RedHat | 6 | s390x | xerces-j2-javadoc-xni | < 2.7.1-12.6.el6_0 | xerces-j2-javadoc-xni-2.7.1-12.6.el6_0.s390x.rpm |
RedHat | 6 | src | xerces-j2 | < 2.7.1-12.6.el6_0 | xerces-j2-2.7.1-12.6.el6_0.src.rpm |
RedHat | 6 | i686 | xerces-j2-scripts | < 2.7.1-12.6.el6_0 | xerces-j2-scripts-2.7.1-12.6.el6_0.i686.rpm |
RedHat | 6 | x86_64 | xerces-j2-debuginfo | < 2.7.1-12.6.el6_0 | xerces-j2-debuginfo-2.7.1-12.6.el6_0.x86_64.rpm |