--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-129d8ca6fc
2024-03-07 22:24:39.963937
--------------------------------------------------------------------------------

Name        : xerces-j2
Product     : Fedora 40
Version     : 2.12.2
Release     : 10.fc40
URL         : https://xerces.apache.org/xerces2-j/
Summary     : Java XML parser
Description :
Welcome to the future! Xerces2 is the next generation of high performance,
fully compliant XML parsers in the Apache Xerces family. This new version of
Xerces introduces the Xerces Native Interface (XNI), a complete framework for
building parser components and configurations that is extremely modular and
easy to program.

The Apache Xerces2 parser is the reference implementation of XNI but other
parser components, configurations, and parsers can be written using the Xerces
Native Interface. For complete design and implementation documents, refer to
the XNI Manual.

Xerces2 is a fully conforming XML Schema processor. For more information,
refer to the XML Schema page.

Xerces2 also provides a complete implementation of the Document Object Model
Level 3 Core and Load/Save W3C Recommendations and provides a complete
implementation of the XML Inclusions (XInclude) W3C Recommendation. It also
provides support for OASIS XML Catalogs v1.1.

Xerces2 is able to parse documents written according to the XML 1.1
Recommendation, except that it does not yet provide an option to enable
normalization checking as described in section 2.13 of this specification. It
also handles name spaces according to the XML Namespaces 1.1 Recommendation,
and will correctly serialize XML 1.1 documents if the DOM level 3 load/save
APIs are in use.

--------------------------------------------------------------------------------
Update Information:

Change for system JDK from 17 to 21.
upstream security release 122.0.6261.94
High CVE-2024-1938: Type Confusion in V8
High CVE-2024-1939: Type Confusion in V8
fixed bug with requires
Automatic update for lucene-9.9.2-1.fc40.
bump java source/target to 1.8, fixes 2266639
--------------------------------------------------------------------------------
ChangeLog:

* Sat Mar  2 2024 Jiri Vanek  - 2.12.2-10
- Rebuilt for java-21-openjdk as system jdk
* Fri Mar  1 2024 Jiri Vanek  - 2.12.2-9
- bump of release for for java-21-openjdk as system jdk
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2123726 - consoleImageViewer crashes at start
        https://bugzilla.redhat.com/show_bug.cgi?id=2123726
  [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40
        https://bugzilla.redhat.com/show_bug.cgi?id=2261062
  [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk
        https://bugzilla.redhat.com/show_bug.cgi?id=2266639
  [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2266934
  [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2266937
  [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta
        https://bugzilla.redhat.com/show_bug.cgi?id=2267486
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 40: xerces-j2 2024-129d8ca6fc

March 7, 2024
Change for system JDK from 17 to 21

Summary

Welcome to the future! Xerces2 is the next generation of high performance,

fully compliant XML parsers in the Apache Xerces family. This new version of

Xerces introduces the Xerces Native Interface (XNI), a complete framework for

building parser components and configurations that is extremely modular and

easy to program.

The Apache Xerces2 parser is the reference implementation of XNI but other

parser components, configurations, and parsers can be written using the Xerces

Native Interface. For complete design and implementation documents, refer to

the XNI Manual.

Xerces2 is a fully conforming XML Schema processor. For more information,

refer to the XML Schema page.

Xerces2 also provides a complete implementation of the Document Object Model

Level 3 Core and Load/Save W3C Recommendations and provides a complete

implementation of the XML Inclusions (XInclude) W3C Recommendation. It also

provides support for OASIS XML Catalogs v1.1.

Xerces2 is able to parse documents written according to the XML 1.1

Recommendation, except that it does not yet provide an option to enable

normalization checking as described in section 2.13 of this specification. It

also handles name spaces according to the XML Namespaces 1.1 Recommendation,

and will correctly serialize XML 1.1 documents if the DOM level 3 load/save

APIs are in use.

Update Information:

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639

Change Log

* Sat Mar 2 2024 Jiri Vanek - 2.12.2-10 - Rebuilt for java-21-openjdk as system jdk * Fri Mar 1 2024 Jiri Vanek - 2.12.2-9 - bump of release for for java-21-openjdk as system jdk

References

[ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : xerces-j2
Product : Fedora 40
Version : 2.12.2
Release : 10.fc40
URL : https://xerces.apache.org/xerces2-j/
Summary : Java XML parser

Related News