Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:1701-1

Опубликовано: 26 июн. 2017
Источник: suse-cvrf

Описание

Security update for jakarta-taglibs-standard

This update for jakarta-taglibs-standard fixes the following issues:

  • CVE-2015-0254: Apache Standard Taglibs allowed remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) x:parse or (2) x:transform JSTL XML tag. (bsc#920813)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
jakarta-taglibs-standard-1.1.1-234.31.1
jakarta-taglibs-standard-javadoc-1.1.1-234.31.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
jakarta-taglibs-standard-1.1.1-234.31.1
jakarta-taglibs-standard-javadoc-1.1.1-234.31.1

Описание

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:jakarta-taglibs-standard-1.1.1-234.31.1
SUSE Linux Enterprise Server 11 SP4:jakarta-taglibs-standard-javadoc-1.1.1-234.31.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:jakarta-taglibs-standard-1.1.1-234.31.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:jakarta-taglibs-standard-javadoc-1.1.1-234.31.1

Ссылки