Lucene search

K
ubuntuUbuntuUSN-2218-1
HistoryMay 21, 2014 - 12:00 a.m.

Xalan-Java vulnerability

2014-05-2100:00:00
ubuntu.com
44

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.5%

Releases

  • Ubuntu 13.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • libxalan2-java - XSL Transformations (XSLT) processor in Java

Details

Nicolas Gregoire discovered that Xalan-Java incorrectly handled certain
properties when the secure processing feature was enabled. An attacker
could possibly use this issue to load arbitrary classes or access external
resources.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.5%