Security Advisory Important: xalan-j2 security update

Advisory: RHSA-2014:0348-1
Type: Security Advisory
Severity: Important
Issued on: 2014-04-01
Last updated on: 2014-04-01
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux HPC Node (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server AUS (v. 6.5)
Red Hat Enterprise Linux Server EUS (v. 6.5.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2014-0107

Details

Updated xalan-j2 packages that fix one security issue are now available for
Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having
Important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)

All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/site/articles/11258

Updated packages

RHEL Desktop Workstation (v. 5 client)

SRPMS:
xalan-j2-2.7.0-6jpp.2.src.rpm     MD5: fcec7804a1902feca207fcca86e8e4dc
SHA-256: a8580ef5afbdd6f94f852abeae8de7340c3bba257328512018d2520eb2b61968
 
IA-32:
xalan-j2-debuginfo-2.7.0-6jpp.2.i386.rpm     MD5: c425a6604ad57bdb27659cf41f0c442e
SHA-256: 0029166ffb2280e8dcc1f0d36ea586578076332c677d621bf21e56b9c17dca08
xalan-j2-demo-2.7.0-6jpp.2.i386.rpm     MD5: 05065f587fb685d27007324fca312d40
SHA-256: a00c4d331c87773a88c08febae27002230ece845be548e62b35320c30ff38680
xalan-j2-javadoc-2.7.0-6jpp.2.i386.rpm     MD5: cb92e1e9430226919200d28e5db4b1d1
SHA-256: 4a78fe9a2d00f14dbecb82d53163ab0e75698c4f3d37b3d2db1887ff9aca4178
 
x86_64:
xalan-j2-debuginfo-2.7.0-6jpp.2.x86_64.rpm     MD5: edef98fefdfa1916afea082a46f1a516
SHA-256: a4f8798988e6bbb8a00a809791a0b8150a0ff86593d5447704160427450bd093
xalan-j2-demo-2.7.0-6jpp.2.x86_64.rpm     MD5: dbce49ce8dd06ab4bed50b38d699a753
SHA-256: 0ff9e5db86a856565a5d9c1f5fcd36e8f99a179c9b5d266704035da4797c905b
xalan-j2-javadoc-2.7.0-6jpp.2.x86_64.rpm     MD5: c522234e25084645e2cc6a2379377b39
SHA-256: af9ab56ca60b72ae5849778d5fd60c7ec9d29910196236d16991d097f25d83e8
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
xalan-j2-2.7.0-6jpp.2.src.rpm     MD5: fcec7804a1902feca207fcca86e8e4dc
SHA-256: a8580ef5afbdd6f94f852abeae8de7340c3bba257328512018d2520eb2b61968
 
IA-32:
xalan-j2-2.7.0-6jpp.2.i386.rpm     MD5: 6e0b9ac8e10aaa72c59f8366e119bdbb
SHA-256: f9eafbac20ceaba132cf33ea89f30d80d629d7a5a8f61f4f53072d6acb90b9bc
xalan-j2-debuginfo-2.7.0-6jpp.2.i386.rpm     MD5: c425a6604ad57bdb27659cf41f0c442e
SHA-256: 0029166ffb2280e8dcc1f0d36ea586578076332c677d621bf21e56b9c17dca08
xalan-j2-demo-2.7.0-6jpp.2.i386.rpm     MD5: 05065f587fb685d27007324fca312d40
SHA-256: a00c4d331c87773a88c08febae27002230ece845be548e62b35320c30ff38680
xalan-j2-javadoc-2.7.0-6jpp.2.i386.rpm     MD5: cb92e1e9430226919200d28e5db4b1d1
SHA-256: 4a78fe9a2d00f14dbecb82d53163ab0e75698c4f3d37b3d2db1887ff9aca4178
xalan-j2-manual-2.7.0-6jpp.2.i386.rpm     MD5: 0eaad25882e71d6c95de09a390481b1b
SHA-256: b60f770fc6776b6b8284f1d19956f2a14fefe22f602c55270e9cefd5b2f3e012
xalan-j2-xsltc-2.7.0-6jpp.2.i386.rpm     MD5: a9a7d7ca50424486db5e8bb1bd642de0
SHA-256: a97c3e58d8ff9535f7039b22cf50d31d18b435d3cfdc548048ed903a3e6893cc
 
IA-64:
xalan-j2-2.7.0-6jpp.2.ia64.rpm     MD5: 2f4eb23ac70d58e2017be638c092064b
SHA-256: 2646babc98b97420334af292d07041fd1f70a8d1ba1dd24240e8ef4ba8f9994c
xalan-j2-debuginfo-2.7.0-6jpp.2.ia64.rpm     MD5: 075f58e69ce09f7bc434bad255bfc163
SHA-256: 906ef7926bd2fb175fbbbc2e9036fcedfece6b8760576d226c62946eb3fb2f62
xalan-j2-demo-2.7.0-6jpp.2.ia64.rpm     MD5: 295e4d2b339fbd69c67d84128d5e7888
SHA-256: 72b0c9fe7e269a62fab09991949001b82826c5437b323a9791cedf127caa2add
xalan-j2-javadoc-2.7.0-6jpp.2.ia64.rpm     MD5: ded72652dd6a0f929f41f2d6cb53abe2
SHA-256: 7a507ff116748ffe2a528cc1df1c5fedf3f392feb13decc536ee43aa1c92fcfa
xalan-j2-manual-2.7.0-6jpp.2.ia64.rpm     MD5: c33900adecb70aced52ee258613ec7e3
SHA-256: e6d288ccd6c62aeb961e3bc3daaa014abbc5146852eb4a159904a30758a44b81
xalan-j2-xsltc-2.7.0-6jpp.2.ia64.rpm     MD5: 13f918d075082cb9bb27311dd5aae496
SHA-256: 03114ebad09a8b78b16aa315e28dc8e48dd4ff208f355e680696c0e5512e2c97
 
PPC:
xalan-j2-2.7.0-6jpp.2.ppc.rpm     MD5: e4f251d20c7b8c6d40fb825ab944e0e2
SHA-256: d00d1a6e5032500ee0d93b04f5600a3550aaaa8018566c092ed595d725466457
xalan-j2-debuginfo-2.7.0-6jpp.2.ppc.rpm     MD5: df692caf58f9228b1c3ced14fc2075c7
SHA-256: 3f85f5ef13bafc1a43b34f5d6d289b8e445eb387a1dc0c6638be536772a9f0bf
xalan-j2-demo-2.7.0-6jpp.2.ppc.rpm     MD5: 26a713402c242f96a8f3f4e83995fe6f
SHA-256: 25aa635490f7aa2496da75ca8bff89282677cac08a41bb1ac1a91a001761a1a1
xalan-j2-javadoc-2.7.0-6jpp.2.ppc.rpm     MD5: 637b466fd9ccf8ef9270d428142cba13
SHA-256: 08d5adbf4f2a39bfe3cc5e20f6966da8852d05bd606ce6623e8703e5a550d4f0
xalan-j2-manual-2.7.0-6jpp.2.ppc.rpm     MD5: a1fc2c0f24583167621b26aa710563c6
SHA-256: 4758c966d2f6a7c46616e399335e47ddb5f1365b0669d4970530b475e851dfdc
xalan-j2-xsltc-2.7.0-6jpp.2.ppc.rpm     MD5: eb969055003e13c977cd1c48cb472eb4
SHA-256: 9c91e7426c1b64d7f8abdf1936d685cc79246c89824536a15ccd6c9aab1a8ba0
 
s390x:
xalan-j2-2.7.0-6jpp.2.s390x.rpm     MD5: c310ebca85aefd6d98c76b73640dd735
SHA-256: 2fc036011dd046cff756c2f3a853312fd946794a27239b82e9e7e5db8315b2d7
xalan-j2-debuginfo-2.7.0-6jpp.2.s390x.rpm     MD5: a559b1248406c09591c75a369301d1ff
SHA-256: ad50a23b9a2f46fe0c1099957a4998ed17a80ee049d796be739143dcddafd029
xalan-j2-demo-2.7.0-6jpp.2.s390x.rpm     MD5: 18f6de1b021060d301a744b51fa7e7dd
SHA-256: c037bf69e7439aaa13f507662e4ae4cc4f949748488c1ba4a7ab3c6551ee6037
xalan-j2-javadoc-2.7.0-6jpp.2.s390x.rpm     MD5: b5cc12970b616e0458683f7b625ac8b0
SHA-256: 0c83cf59c5e954db8b3fcd334a05b3ead954d9bab9c223610ebdc23a70657546
xalan-j2-manual-2.7.0-6jpp.2.s390x.rpm     MD5: e73a4e604e8e8a83cfb8625a8ed941ae
SHA-256: 5497b25e677e227f0b000713058b9006978c590d305efec0fa0bdffd50d1012d
xalan-j2-xsltc-2.7.0-6jpp.2.s390x.rpm     MD5: ffa60afe4e1ca8f9bf8d2a3965c3122c
SHA-256: 7b23d467d8a6e401e77510d41458eeec2598b4d7064d4d50c4fbd8b2813aadcd
 
x86_64:
xalan-j2-2.7.0-6jpp.2.x86_64.rpm     MD5: 5d3202e5487b9d06a070d6e3064eebee
SHA-256: b6d168b0e1851853434ba0585f3d1056de037912b04e243eb51008aa390e5953
xalan-j2-debuginfo-2.7.0-6jpp.2.x86_64.rpm     MD5: edef98fefdfa1916afea082a46f1a516
SHA-256: a4f8798988e6bbb8a00a809791a0b8150a0ff86593d5447704160427450bd093
xalan-j2-demo-2.7.0-6jpp.2.x86_64.rpm     MD5: dbce49ce8dd06ab4bed50b38d699a753
SHA-256: 0ff9e5db86a856565a5d9c1f5fcd36e8f99a179c9b5d266704035da4797c905b
xalan-j2-javadoc-2.7.0-6jpp.2.x86_64.rpm     MD5: c522234e25084645e2cc6a2379377b39
SHA-256: af9ab56ca60b72ae5849778d5fd60c7ec9d29910196236d16991d097f25d83e8
xalan-j2-manual-2.7.0-6jpp.2.x86_64.rpm     MD5: 593618fc88a7011282a759f87175520d
SHA-256: 5441b555eb82cdcfdcd6385cda035550364b8ee750b7e19b3b5ee7dced8c3827
xalan-j2-xsltc-2.7.0-6jpp.2.x86_64.rpm     MD5: 097097cef16c345aab616f3ec9f5b825
SHA-256: 04d89c0e60c9595a5f216ebe2d6d8122e3ac3945fdf08f0d122da52b70a5cdec
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
xalan-j2-2.7.0-6jpp.2.src.rpm     MD5: fcec7804a1902feca207fcca86e8e4dc
SHA-256: a8580ef5afbdd6f94f852abeae8de7340c3bba257328512018d2520eb2b61968
 
IA-32:
xalan-j2-2.7.0-6jpp.2.i386.rpm     MD5: 6e0b9ac8e10aaa72c59f8366e119bdbb
SHA-256: f9eafbac20ceaba132cf33ea89f30d80d629d7a5a8f61f4f53072d6acb90b9bc
xalan-j2-debuginfo-2.7.0-6jpp.2.i386.rpm     MD5: c425a6604ad57bdb27659cf41f0c442e
SHA-256: 0029166ffb2280e8dcc1f0d36ea586578076332c677d621bf21e56b9c17dca08
xalan-j2-manual-2.7.0-6jpp.2.i386.rpm     MD5: 0eaad25882e71d6c95de09a390481b1b
SHA-256: b60f770fc6776b6b8284f1d19956f2a14fefe22f602c55270e9cefd5b2f3e012
xalan-j2-xsltc-2.7.0-6jpp.2.i386.rpm     MD5: a9a7d7ca50424486db5e8bb1bd642de0
SHA-256: a97c3e58d8ff9535f7039b22cf50d31d18b435d3cfdc548048ed903a3e6893cc
 
x86_64:
xalan-j2-2.7.0-6jpp.2.x86_64.rpm     MD5: 5d3202e5487b9d06a070d6e3064eebee
SHA-256: b6d168b0e1851853434ba0585f3d1056de037912b04e243eb51008aa390e5953
xalan-j2-debuginfo-2.7.0-6jpp.2.x86_64.rpm     MD5: edef98fefdfa1916afea082a46f1a516
SHA-256: a4f8798988e6bbb8a00a809791a0b8150a0ff86593d5447704160427450bd093
xalan-j2-manual-2.7.0-6jpp.2.x86_64.rpm     MD5: 593618fc88a7011282a759f87175520d
SHA-256: 5441b555eb82cdcfdcd6385cda035550364b8ee750b7e19b3b5ee7dced8c3827
xalan-j2-xsltc-2.7.0-6jpp.2.x86_64.rpm     MD5: 097097cef16c345aab616f3ec9f5b825
SHA-256: 04d89c0e60c9595a5f216ebe2d6d8122e3ac3945fdf08f0d122da52b70a5cdec
 
Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
IA-32:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
Red Hat Enterprise Linux HPC Node (v. 6)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
IA-32:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
PPC:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
s390x:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
Red Hat Enterprise Linux Server AUS (v. 6.5)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
Red Hat Enterprise Linux Server EUS (v. 6.5.z)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
IA-32:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
PPC:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
s390x:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
xalan-j2-2.7.0-9.9.el6_5.src.rpm     MD5: a8cdcb272a67eb4f8616dabb4d011b56
SHA-256: 09633559e9428200a942974cfe78dde24cff9ac4b84265e365063610cb50300f
 
IA-32:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
x86_64:
xalan-j2-2.7.0-9.9.el6_5.noarch.rpm     MD5: 502ef34e5d0de5631a61ad3bc52bffc6
SHA-256: 9954595fbd4d3dd078eab5672cfbd862bc330bf85465ff519d270c99a4065844
xalan-j2-demo-2.7.0-9.9.el6_5.noarch.rpm     MD5: 5a3adab913fe029856d8df0b9a00244f
SHA-256: 494a06d7bfed6398f41f3df8f6bb261a40855262dd637dd77f959b2746bf61be
xalan-j2-javadoc-2.7.0-9.9.el6_5.noarch.rpm     MD5: f44666d04eede7ca01221eaad4566960
SHA-256: 68191a86313bf93d3b67386c02f2e7b74d96641c6c89524d6246f696303da7f2
xalan-j2-manual-2.7.0-9.9.el6_5.noarch.rpm     MD5: 10b7ce109fccbccedbdf1193757dfa19
SHA-256: e1e8286b998e0d20a437e49f14b06934c62ea258b8ec5baf7282d290c7148c06
xalan-j2-xsltc-2.7.0-9.9.el6_5.noarch.rpm     MD5: 32ddb9c3bdf9903ce64fa8edfecd22e4
SHA-256: aef9be228bbc297fdc44f698cc0cac322e9a5a42f1da6fac0b6698d032fd1ea2
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

1080248 - CVE-2014-0107 Xalan-Java: insufficient constraints in secure processing feature


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/