Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 33: 2021-8015a8cdc4 Critical: dom4j XML Injection Security Fix

fedora
Calendar Grey May 12, 2021
Dist Fedora Esm H88
Significant security patch for dom4j on Fedora 33 resolves vulnerabilities related to XML injection with essential upgrades.
- Security fix for CVE-2018-1000632 - Update to upstream 2.0.3 bugfix release - Fix Fedora 34 FTBFS

Summary

dom4j is an Open Source XML framework for Java. dom4j allows you to read,

write, navigate, create and modify XML documents. dom4j integrates with

DOM and SAX and is seamlessly integrated with full XPath support.

- Security fix for CVE-2018-1000632 - Update to upstream 2.0.3 bugfix release -Fix Fedora 34 FTBFS

* Thu Apr 29 2021 Hans de Goede - 0:2.0.3-1

- New upstream version 2.0.3

- Fix CVE-2018-1000632 (rhbz#1620535)

* Thu Apr 29 2021 Hans de Goede - 0:2.0.0-14

- Drop the org.dom4j.datatype bits, these depend on the obsolete msv project and

no Fedora packages runtime require msv, so no package seem to need these bits.

- Drop dom4j-demo and dom4j-manual Obsoletes, these no longer exist since F27.

- Fix FTBFS (rhbz#1923601)

* Tue Jan 26 2021 Fedora Release Engineering - 0:2.0.0-13

- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

[ 1 ] Bug #1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents

https://bugzilla.redhat.com/show_bug.cgi?id=1620529

su -c 'dnf upgrade --advisory FEDORA-2021-8015a8cdc4' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 2.0.3
Release: 1.fc33
Summary: Open Source XML framework for Java

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here