Описание
Security update for jakarta-taglibs-standard
This update for jakarta-taglibs-standard fixes the following issues:
- CVE-2015-0254: Apache Standard Taglibs allowed remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) x:parse or (2) x:transform JSTL XML tag. (bsc#920813)
Список пакетов
SUSE Linux Enterprise Server 12 SP2
jakarta-taglibs-standard-1.1.1-255.2
jakarta-taglibs-standard-javadoc-1.1.1-255.2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
jakarta-taglibs-standard-1.1.1-255.2
jakarta-taglibs-standard-javadoc-1.1.1-255.2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
jakarta-taglibs-standard-1.1.1-255.2
jakarta-taglibs-standard-javadoc-1.1.1-255.2
Ссылки
- Link for SUSE-SU-2017:1568-1
- E-Mail link for SUSE-SU-2017:1568-1
- SUSE Security Ratings
- SUSE Bug 920813
- SUSE CVE CVE-2015-0254 page
Описание
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2:jakarta-taglibs-standard-1.1.1-255.2
SUSE Linux Enterprise Server 12 SP2:jakarta-taglibs-standard-javadoc-1.1.1-255.2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:jakarta-taglibs-standard-1.1.1-255.2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:jakarta-taglibs-standard-javadoc-1.1.1-255.2
Ссылки
- CVE-2015-0254
- SUSE Bug 920813