{"id":"MGASA-2015-0211","summary":"Updated springframework packages fix CVE-2014-0225","details":"Updated springframework packages fix security vulnerabilities:\n\nWhen processing user provided XML documents, the Spring Framework did not\ndisable by default the resolution of URI references in a DTD declaration. By\nobserving differences in response times, an attacker could then identify\nvalid IP addresses on the internal network with functioning web servers\n(CVE-2014-0225).\n","modified":"2026-04-16T01:45:57.344542099Z","published":"2015-05-11T20:10:38Z","upstream":["CVE-2014-0225"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0211.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15886"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2015-May/157348.html"}],"affected":[{"package":{"name":"springframework","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/springframework?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.4-2.3.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0211.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}