Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Scientific Linux: SLSA-2014:0348-1 Critical: Xalan-Java Remote Code Exec

Scientific Large Esm H446
Important: xalan-j2 security update
Date: Tue, 1 Apr 2014 10:24:32 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 6x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <53319B9E.9010807@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
man-pages-overrides-6.5.3-1.el6_5.noarch.rpm
resource-agents-3.9.2-40.el6_5.7.i686.rpm
resource-agents-sap-3.9.2-40.el6_5.7.i686.rpm
star-1.5-11.1.el6_5.i686.rpm

x86_64:
man-pages-overrides-6.5.3-1.el6_5.noarch.rpm
resource-agents-3.9.2-40.el6_5.7.x86_64.rpm
resource-agents-sap-3.9.2-40.el6_5.7.x86_64.rpm
star-1.5-11.1.el6_5.x86_64.rpm
Date: Tue, 1 Apr 2014 19:33:53 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Important: xalan-j2 on SL5.x, SL6.x i386/x86_64
MIME-Version: 1.0

Synopsis: Important: xalan-j2 security update
Advisory ID: SLSA-2014:0348-1
Issue Date: 2014-04-01
CVE Numbers: CVE-2014-0107
--

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features. A
remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses Xalan-
Java. (CVE-2014-0107)
--

SL5
 x86_64
 xalan-j2-2.7.0-6jpp.2.x86_64.rpm
 xalan-j2-debuginfo-2.7.0-6jpp.2.x86_64.rpm
 xalan-j2-manual-2.7.0-6jpp.2.x86_64.rpm
 xalan-j2-xsltc-2.7.0-6jpp.2.x86_64.rpm
 xalan-j2-demo-2.7.0-6jpp.2.x86_64.rpm
 xalan-j2-javadoc-2.7.0-6jpp.2.x86_64.rpm
 i386
 xalan-j2-2.7.0-6jpp.2.i386.rpm
 xalan-j2-debuginfo-2.7.0-6jpp.2.i386.rpm
 xalan-j2-manual-2.7.0-6jpp.2.i386.rpm
 xalan-j2-xsltc-2.7.0-6jpp.2.i386.rpm
 xalan-j2-demo-2.7.0-6jpp.2.i386.rpm
 xalan-j2-javadoc-2.7.0-6jpp.2.i386.rpm
SL6
 noarch
 xalan-j2-2.7.0-9.9.el6_5.noarch.rpm
 xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm
 xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm
 xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm
 xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm

- Scientific Linux Development Team