Re: Xerces and security vulnerabilities

2015-11-05 Thread Michael Glavassevich
Updating JIRA (e.g. marking issues resolved in 2.12?), writing the release notes and website updates for starters... Just never find the time to start pushing those forward. Michael Glavassevich XML Technologies and WAS Development IBM Toronto Lab E-mail: mrgla...@ca.ibm.com E-mail: mrgla...@apa

Re: Xerces and security vulnerabilities

2015-11-05 Thread Gary Gregory
What kind of help do you need? Gary On Nov 5, 2015 12:20 PM, "Michael Glavassevich" wrote: > Yes, but need help from volunteers with more time to prepare a Xerces > release. > > And should probably also have an xml-commons release (to include in > Xerces) that contains this: > http://svn.apache.

Re: Xerces and security vulnerabilities

2015-11-05 Thread Michael Glavassevich
Yes, but need help from volunteers with more time to prepare a Xerces release. And should probably also have an xml-commons release (to include in Xerces) that contains this: http://svn.apache.org/viewvc?view=revision&revision=1357443 Similar hash collision fix as the ones implemented in Xerces

Re: Xerces and security vulnerabilities

2015-11-05 Thread Gary Gregory
Any thoughts on pushing out a release to pick up the one fix? (And whatever else is in trunk since 2.11) Gary On Thu, Nov 5, 2015 at 9:14 AM -0800, "Michael Glavassevich" mailto:mrgla...@ca.ibm.com>> wrote: Peter Major wrote on 11/05/2015 02:24:58 AM: > How about these then? > https://bugz

Re: Xerces and security vulnerabilities

2015-11-05 Thread Michael Glavassevich
Peter Major wrote on 11/05/2015 02:24:58 AM: > How about these then? > https://bugzilla.redhat.com/show_bug.cgi?id=1273638 Xerces doesn't support that property. > https://bugzilla.redhat.com/show_bug.cgi?id=1273645 Xerces doesn't have a StAX XML parser. > https://bugzilla.redhat.com/show_bug.

Re: Xerces and security vulnerabilities

2015-11-04 Thread Peter Major
How about these then? https://bugzilla.redhat.com/show_bug.cgi?id=1273638 https://bugzilla.redhat.com/show_bug.cgi?id=1273645 https://bugzilla.redhat.com/show_bug.cgi?id=1273637 2015. 11. 04. 16:38 keltezéssel, Michael Glavassevich írta: As they did not disclose any details in these reports, onl

Re: Xerces and security vulnerabilities

2015-11-04 Thread Michael Glavassevich
As they did not disclose any details in these reports, only Oracle would know. Thanks. Michael Glavassevich XML Technologies and WAS Development IBM Toronto Lab E-mail: mrgla...@ca.ibm.com E-mail: mrgla...@apache.org Peter Major wrote on 11/04/2015 03:36:26 AM: > Hi, > > it appears that Orac

Xerces and security vulnerabilities

2015-11-04 Thread Peter Major
Hi, it appears that Oracle has fixed some XML parsing related security vulnerabilities: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4803 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4893 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4911 Is it possible that these