Mageia 2019-0077: dom4j security update
Summary
dom4j version prior to version 2.1.1 contains an XML Injection vulnerability
in Class: Element. Methods: addElement, addAttribute that can result in an
attacker tampering with XML documents through XML injection. This attack
appears to be exploitable via an attacker specifying attributes or elements
in the XML document (CVE-2018-1000632).
References
- https://bugs.mageia.org/show_bug.cgi?id=23677
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000632
Resolution
MGASA-2019-0077 - Updated dom4j packages fix security vulnerability
SRPMS
- 6/core/dom4j-1.6.1-28.1.mga6