File tree Expand file tree Collapse file tree
toolkit/resources/manifests/package Expand file tree Collapse file tree Original file line number Diff line number Diff line change 11{
22 "Signatures" : {
3- "docbook-xsl-1.79.1.tar.bz2" : " 725f452e12b296956e8bfb876ccece71eeecdd14b94f667f3ed9091761a4a968"
3+ "docbook-xsl-1.79.1.tar.bz2" : " 725f452e12b296956e8bfb876ccece71eeecdd14b94f667f3ed9091761a4a968" ,
4+ "xalan-j_2_7_3-bin.tar.gz" : " c3a36e027f91acbec3f2139343a4798a943f8b2957aab1cfb2eb57f4aeadccbc"
45 }
56}
Original file line number Diff line number Diff line change 11Summary: Docbook-xsl-1.79.1
22Name: docbook-style-xsl
33Version: 1.79.1
4- Release: 13 %{?dist }
5- License: ASL 2.0
4+ Release: 14 %{?dist }
5+ License: D MIT
66Vendor: Microsoft Corporation
77Distribution: Mariner
88Group: Development/Tools
99URL: https://www.docbook.org
1010Source0: http://downloads.sourceforge.net/docbook/docbook-xsl-%{version }.tar.bz2
11+ # CVE-2022-34169: xalan 2.7.2 has security issue that is solved in 2.7.3
12+ Source1: https://dlcdn.apache.org/xalan/xalan-j/binaries/xalan-j_2_7_3-bin.tar.gz
1113BuildRequires: libxml2
1214BuildRequires: zip
1315Requires: docbook-dtd-xml
@@ -24,6 +26,12 @@ allowing you to utilize transformations already written for that standard.
2426
2527%prep
2628%setup -q -n docbook-xsl-%{version }
29+ # CVE-2022-34169: xalan 2.7.2 has security issue that is solved by 2.7.3,
30+ # so replace the embedded jar files in docbook-xsl release before continuing
31+ mkdir ./CVE-2022-34169
32+ tar -xf %{SOURCE1 } -C ./CVE-2022-34169
33+ mv ./CVE-2022-34169/xalan-j_2_7_3/* .jar ./tools/lib/.
34+ rm -rf ./CVE-2022-34169
2735
2836%build
2937zip -d tools/lib/jython.jar Lib/distutils/command/wininst-6.exe
102110%{_docdir }/*
103111
104112%changelog
113+ * Mon Jun 03 2024 Brian Fjeldstad <bfjelds@microsoft.com> - 1.79.1-14
114+ - Fix CVE-2022-34169 by using newer release of xalan
115+ - License should be DMIT. License verified
116+
105117* Sat May 09 2020 Nick Samson <nisamson@microsoft.com> - 1.79.1-10
106118- Added %%license line automatically
107119
Original file line number Diff line number Diff line change @@ -197,7 +197,7 @@ createrepo_c-0.17.5-1.cm2.aarch64.rpm
197197libxml2-2.10.4-3.cm2.aarch64.rpm
198198libxml2-devel-2.10.4-3.cm2.aarch64.rpm
199199docbook-dtd-xml-4.5-11.cm2.noarch.rpm
200- docbook-style-xsl-1.79.1-13 .cm2.noarch.rpm
200+ docbook-style-xsl-1.79.1-14 .cm2.noarch.rpm
201201libsepol-3.2-2.cm2.aarch64.rpm
202202glib-2.71.0-2.cm2.aarch64.rpm
203203libltdl-2.4.6-8.cm2.aarch64.rpm
Original file line number Diff line number Diff line change @@ -197,7 +197,7 @@ createrepo_c-0.17.5-1.cm2.x86_64.rpm
197197libxml2-2.10.4-3.cm2.x86_64.rpm
198198libxml2-devel-2.10.4-3.cm2.x86_64.rpm
199199docbook-dtd-xml-4.5-11.cm2.noarch.rpm
200- docbook-style-xsl-1.79.1-13 .cm2.noarch.rpm
200+ docbook-style-xsl-1.79.1-14 .cm2.noarch.rpm
201201libsepol-3.2-2.cm2.x86_64.rpm
202202glib-2.71.0-2.cm2.x86_64.rpm
203203libltdl-2.4.6-8.cm2.x86_64.rpm
Original file line number Diff line number Diff line change @@ -56,7 +56,7 @@ debugedit-debuginfo-5.0-2.cm2.aarch64.rpm
5656diffutils-3.8-2.cm2.aarch64.rpm
5757diffutils-debuginfo-3.8-2.cm2.aarch64.rpm
5858docbook-dtd-xml-4.5-11.cm2.noarch.rpm
59- docbook-style-xsl-1.79.1-13 .cm2.noarch.rpm
59+ docbook-style-xsl-1.79.1-14 .cm2.noarch.rpm
6060dwz-0.14-2.cm2.aarch64.rpm
6161dwz-debuginfo-0.14-2.cm2.aarch64.rpm
6262e2fsprogs-1.46.5-3.cm2.aarch64.rpm
Original file line number Diff line number Diff line change @@ -59,7 +59,7 @@ debugedit-debuginfo-5.0-2.cm2.x86_64.rpm
5959diffutils-3.8-2.cm2.x86_64.rpm
6060diffutils-debuginfo-3.8-2.cm2.x86_64.rpm
6161docbook-dtd-xml-4.5-11.cm2.noarch.rpm
62- docbook-style-xsl-1.79.1-13 .cm2.noarch.rpm
62+ docbook-style-xsl-1.79.1-14 .cm2.noarch.rpm
6363dwz-0.14-2.cm2.x86_64.rpm
6464dwz-debuginfo-0.14-2.cm2.x86_64.rpm
6565e2fsprogs-1.46.5-3.cm2.x86_64.rpm
You can’t perform that action at this time.
0 commit comments