Recent Articles

Quark, EMC Look At XML Authoring And Microsoft Word
A skilled construction crew might be able to build houses using 16th-century techniques, and there’s a fair market for clothing that’s created by hand. At the same...

Without An XML Sitemap Does Your Site Still Get...
This weekend I was doing a little housekeeping on some of my domains and hosting accounts and decided to test and see if it was possible to get a website indexed...

XML Based Business Process Management
I got an update on Vitria for the first time in a few years a little while back. Vitria started back in 1994 with Enterprise Application Integration capabilities and has...

Microsoft Ordered To Pay XML Firm $200 Million
Sometimes, the figurative little guy wins. Sometimes, the figurative little guy is an XML company. And this is both of those times, since Microsoft's been ordered to pay...

08.13.09

XML Library Flaws Found Far And Wide

By Doug Caverly

XML professionals might want to raise shields and go to red - or at least yellow - alert.  Multiple flaws in popular XML libraries have been discovered, and experts believe that the fallout could be pretty severe.

Affected libraries include those from Apache, Python, and Sun, according to a statement from Codenomicon.  What’s more, the problems aren’t at all new, as they were discovered in early 2009, and the official release indicates, “The impact of the discovered vulnerabilities varies from denial-of-service attacks to potential execution of malicious code on affected systems.”

Obviously, this isn’t good news for members of the XML community.

Download a Free Trial of Ektron CMS400.NET

The potential saving grace is that Codenomicon tried to keep everything under its hat until some fixes could be readied.  So, as long as the people behind the XML libraries do their job and you update your vulnerable software before someone takes a crack at the system, everything should be fine.

Also, if you’re curious about how Codenomicon came across all of these problems, the company’s supposed to release its new testing solution, DEFENSICS for XML, at a security conference in September.

Hopefully this scare will wind up being more of an educational opportunity than a disastrous development, then.


About the Author:
Doug is a staff writer for WebProNews. Visit WebProNews for the latest eBusiness news.
About xmlProNews

xmlProNews is a collection of news and commentary designed to keep you in step with the ever evolving landscape of XML environments. News and Advice for XML Professionals





xmlProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com SysAdminNews.com






-- XMLProNewsis an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2009 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


XMLProNews