A possible denial of service issue from overflowing an array has been fixed in the xerces-j2 package.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0205.json"