PT-2008-6893 · Libxslt+1 · Libxslt+1

Publicado

1970-01-01

·

Atualizado

2018-10-11

·

CVE-2008-2935

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxslt versions 1.1.8 through 1.1.24 libxslt-devel-1.1.11 libxslt-python-1.1.11 libxslt1-dev libxslt1-dbg libxslt1.1
Description The issue allows context-dependent attackers to execute arbitrary code via an XML file containing a long string as an argument in the XSL input, potentially leading to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations For libxslt versions 1.1.8 through 1.1.24, update to a version later than 1.1.24. For libxslt-devel-1.1.11, consider disabling the vulnerable package until a patch is available. For libxslt-python-1.1.11, restrict access to the package to minimize the risk of exploitation. For libxslt1-dev, libxslt1-dbg, and libxslt1.1, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for libxslt (до версии 1.1.24-r1) in Gentoo Linux.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01767
BDU:2015-01768
BDU:2015-01769
BDU:2015-07413
BDU:2015-07415
BDU:2015-07416
BDU:2015-08444
BDU:2015-08445
BDU:2015-08446
BDU:2015-09347
CVE-2008-2935
DSA-1624-1
DTSA-152-1
RHSA-2008:0649
RHSA-2008_0649

Produtos afetados

Red Hat
Libxslt