Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 22.18-1 Security Notice: Xalan-Java Class Access Vulnerability

ubuntu
Calendar Grey May 21, 2014
Scroller Ubuntu
Xalan-Java could be exploited to load external classes; patch for Ubuntu systems is advised.
Xalan-Java could be made to load arbitrary classes or access external resources.

Summary

Xalan-Java could be made to load arbitrary classes or access external

resources.

Software Description:

- libxalan2-java: XSL Transformations (XSLT) processor in Java

Details:

Nicolas Gregoire discovered that Xalan-Java incorrectly handled certain

properties when the secure processing feature was enabled. An attacker

could possibly use this issue to load arbitrary classes or access external

resources.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libxalan2-java                  2.7.1-8ubuntu0.1
  libxsltc-java                   2.7.1-8ubuntu0.1

Ubuntu 12.04 LTS:
  libxalan2-java                  2.7.1-7ubuntu0.1
  libxsltc-java                   2.7.1-7ubuntu0.1

Ubuntu 10.04 LTS:
  libxalan2-java                  2.7.1-5ubuntu1.1
  libxalan2-java-gcj              2.7.1-5ubuntu1.1
  libxsltc-java                   2.7.1-5ubuntu1.1
  libxsltc-java-gcj               2.7.1-5ubuntu1.1

After a standard system update you need to reboot your computer to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-2218-1

CVE-2014-0107

Severity
important
Lowest
Low
Medium
High
Critical

May 21, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.