|
|
Log in / Subscribe / Register

Mageia alert MGASA-2015-0211 (springframework)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2015-0211: Updated springframework packages fix CVE-2014-0225
Date:  Mon, 11 May 2015 22:11:13 +0200
Message-ID:  <20150511201113.24EE743AA1@valstar.mageia.org>

MGASA-2015-0211 - Updated springframework packages fix CVE-2014-0225 Publication date: 11 May 2015 URL: http://advisories.mageia.org/MGASA-2015-0211.html Type: security Affected Mageia releases: 4 CVE: CVE-2014-0225 Description: Updated springframework packages fix security vulnerabilities: When processing user provided XML documents, the Spring Framework did not disable by default the resolution of URI references in a DTD declaration. By observing differences in response times, an attacker could then identify valid IP addresses on the internal network with functioning web servers (CVE-2014-0225). References: - https://bugs.mageia.org/show_bug.cgi?id=15886 - https://lists.fedoraproject.org/pipermail/package-announc... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0225 SRPMS: - 4/core/springframework-3.1.4-2.3.mga4


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds