Bug#1084985: fop: CVE-2024-28168

Moritz Mühlenhoff jmm at inutil.org
Sat Oct 12 10:38:24 BST 2024


Source: fop
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for fop.

CVE-2024-28168[0]:
| Improper Restriction of XML External Entity Reference ('XXE')
| vulnerability in Apache XML Graphics FOP.  This issue affects Apache
| XML Graphics FOP: 2.9.  Users are recommended to upgrade to version
| 2.10, which fixes the issue.

https://www.openwall.com/lists/oss-security/2024/10/09/1
https://issues.apache.org/jira/browse/FOP-3168
https://github.com/apache/xmlgraphics-fop/commit/d96ba9a11710d02716b6f4f6107ebfa9ccec7134


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-28168
    https://www.cve.org/CVERecord?id=CVE-2024-28168

Please adjust the affected versions in the BTS as needed.



More information about the pkg-java-maintainers mailing list