MGASA-2014-0558

Source
https://advisories.mageia.org/MGASA-2014-0558.html
Import Source
https://advisories.mageia.org/MGASA-2014-0558.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0558
Related
Published
2014-12-31T12:28:04Z
Modified
2014-12-31T12:19:36Z
Summary
Updated xml-security packages fix CVE-2013-4517
Details

Updated xml-security packages fixes security vulnerability:

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures (CVE-2013-4517).

References
Credits

Affected packages

Mageia:4 / xml-security

Package

Name
xml-security
Purl
pkg:rpm/mageia/xml-security?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.7-1.mga4

Ecosystem specific

{
    "section": "core"
}