UbuntuUpdates.org

Package "fop-doc"

Name: fop-doc

Description:

XML formatter driven by XSL Formatting Objects (doc)

Latest version: 1:1.1.dfsg-2ubuntu1.1
Release: trusty (14.04)
Level: updates
Repository: main
Head package: fop
Homepage: http://xmlgraphics.apache.org/fop/

Links


Download "fop-doc"


Other versions of "fop-doc" in Trusty

Repository Area Version
base main 1:1.1.dfsg-2ubuntu1
security main 1:1.1.dfsg-2ubuntu1.1

Changelog

Version: 1:1.1.dfsg-2ubuntu1.1 2017-05-09 17:06:33 UTC

  fop (1:1.1.dfsg-2ubuntu1.1) trusty-security; urgency=medium

  * SECURITY UPDATE: SSRF through external DTD resolution
    - debian/patches/CVE-2017-5661.patch: disable external DTD resolution
      in src/java/org/apache/fop/cli/InputHandler.java,
      src/java/org/apache/fop/servlet/FopServlet.java.
    - Thanks to Debian for the patch backport.
    - CVE-2017-5661

 -- Marc Deslauriers <email address hidden> Thu, 04 May 2017 12:56:32 -0400

CVE-2017-5661 In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S



About   -   Send Feedback to @ubuntu_updates