[SECURITY] Fedora 40 Update: xerces-j2-2.12.2-10.fc40

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-129d8ca6fc
2024-03-07 22:24:39.963937
--------------------------------------------------------------------------------

Name        : xerces-j2
Product     : Fedora 40
Version     : 2.12.2
Release     : 10.fc40
URL         : http://xerces.apache.org/xerces2-j/
Summary     : Java XML parser
Description :
Welcome to the future! Xerces2 is the next generation of high performance,
fully compliant XML parsers in the Apache Xerces family. This new version of
Xerces introduces the Xerces Native Interface (XNI), a complete framework for
building parser components and configurations that is extremely modular and
easy to program.

The Apache Xerces2 parser is the reference implementation of XNI but other
parser components, configurations, and parsers can be written using the Xerces
Native Interface. For complete design and implementation documents, refer to
the XNI Manual.

Xerces2 is a fully conforming XML Schema processor. For more information,
refer to the XML Schema page.

Xerces2 also provides a complete implementation of the Document Object Model
Level 3 Core and Load/Save W3C Recommendations and provides a complete
implementation of the XML Inclusions (XInclude) W3C Recommendation. It also
provides support for OASIS XML Catalogs v1.1.

Xerces2 is able to parse documents written according to the XML 1.1
Recommendation, except that it does not yet provide an option to enable
normalization checking as described in section 2.13 of this specification. It
also handles name spaces according to the XML Namespaces 1.1 Recommendation,
and will correctly serialize XML 1.1 documents if the DOM level 3 load/save
APIs are in use.

--------------------------------------------------------------------------------
Update Information:

Change for system JDK from 17 to 21.
upstream security release 122.0.6261.94
High CVE-2024-1938: Type Confusion in V8
High CVE-2024-1939: Type Confusion in V8
fixed bug with requires
Automatic update for lucene-9.9.2-1.fc40.
bump java source/target to 1.8, fixes 2266639
--------------------------------------------------------------------------------
ChangeLog:

* Sat Mar  2 2024 Jiri Vanek <jvanek@xxxxxxxxxx> - 2.12.2-10
- Rebuilt for java-21-openjdk as system jdk
* Fri Mar  1 2024 Jiri Vanek <jvanek@xxxxxxxxxx> - 2.12.2-9
- bump of release for for java-21-openjdk as system jdk
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2123726 - consoleImageViewer crashes at start
        https://bugzilla.redhat.com/show_bug.cgi?id=2123726
  [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40
        https://bugzilla.redhat.com/show_bug.cgi?id=2261062
  [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk
        https://bugzilla.redhat.com/show_bug.cgi?id=2266639
  [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2266934
  [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2266937
  [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta
        https://bugzilla.redhat.com/show_bug.cgi?id=2267486
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Users]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Photos]     [KDE Users]

  Powered by Linux