On Thu, May 4, 2017 at 9:43 AM, Nicolas Grégoire <nicolas.grego...@agarri.fr
> wrote:

> Hello,
>
> I recently identified several vulnerabilities affecting Xalan-C v1.11.
> While researching them, I noticed that a few of them are already listed
> in the public bug tracker.
>
> As an example, ticket XALANC-762 (created on 03/Apr/15) refers to a
> stack-based buffer overflow during conversion of large numbers:
> https://issues.apache.org/jira/browse/XALANC-762
>
> Should I report the other bugs I found in the bug tracker (or somewhere
> else like a private mailing list)? Is there still any active
> development of this code base?
>

I've not see much activity on Xalan-C. Recording bugs you find is always
nice but I am not sure you'll see any fixes. Hopefully someone else will
pipe in.

Gary


> Regards,
> Nicolas Grégoire
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: dev-unsubscr...@xalan.apache.org
> For additional commands, e-mail: dev-h...@xalan.apache.org
>
>


-- 
E-Mail: garydgreg...@gmail.com | ggreg...@apache.org
Java Persistence with Hibernate, Second Edition
<https://www.amazon.com/gp/product/1617290459/ref=as_li_tl?ie=UTF8&camp=1789&creative=9325&creativeASIN=1617290459&linkCode=as2&tag=garygregory-20&linkId=cadb800f39946ec62ea2b1af9fe6a2b8>

<http:////ir-na.amazon-adsystem.com/e/ir?t=garygregory-20&l=am2&o=1&a=1617290459>
JUnit in Action, Second Edition
<https://www.amazon.com/gp/product/1935182021/ref=as_li_tl?ie=UTF8&camp=1789&creative=9325&creativeASIN=1935182021&linkCode=as2&tag=garygregory-20&linkId=31ecd1f6b6d1eaf8886ac902a24de418%22>

<http:////ir-na.amazon-adsystem.com/e/ir?t=garygregory-20&l=am2&o=1&a=1935182021>
Spring Batch in Action
<https://www.amazon.com/gp/product/1935182951/ref=as_li_tl?ie=UTF8&camp=1789&creative=9325&creativeASIN=1935182951&linkCode=%7B%7BlinkCode%7D%7D&tag=garygregory-20&linkId=%7B%7Blink_id%7D%7D%22%3ESpring+Batch+in+Action>
<http:////ir-na.amazon-adsystem.com/e/ir?t=garygregory-20&l=am2&o=1&a=1935182951>
Blog: http://garygregory.wordpress.com
Home: http://garygregory.com/
Tweet! http://twitter.com/GaryGregory

Reply via email to