Re: Xerces and security vulnerabilities
Peter Major <[email protected]> Thu, 5 Nov 2015 07:24:58 +0000
| Newsgroups | gmane.text.xml.xerces-j.user |
|---|---|
| Message-ID | <[email protected]> |
How about these then? https://bugzilla.redhat.com/show_bug.cgi?id=1273638 https://bugzilla.redhat.com/show_bug.cgi?id=1273645 https://bugzilla.redhat.com/show_bug.cgi?id=1273637 2015. 11. 04. 16:38 keltezéssel, Michael Glavassevich Ãrta: > As they did not disclose any details in these reports, only Oracle would > know. > > Thanks. > > Michael Glavassevich > XML Technologies and WAS Development > IBM Toronto Lab > E-mail: [email protected] > E-mail: [email protected] > > Peter Major <[email protected]> wrote on 11/04/2015 03:36:26 AM: > >> Hi, >> >> it appears that Oracle has fixed some XML parsing related security >> vulnerabilities: >> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4803 >> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4893 >> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4911 >> >> Is it possible that these also affect Xerces 2.11.0? >> >> Regards, >> Peter