PT-2012-1042 · Libxslt+4 · Libxslt+4

Inferno

·

Publicado

2012-08-31

·

Atualizado

2024-06-15

·

CVE-2012-2893

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxslt versions prior to 22.0.1229.79
Description The issue is related to a double free vulnerability in libxslt, which can be exploited by remote attackers to cause a denial of service or possibly have other unspecified impacts. This is achieved through vectors related to XSL transforms. Additionally, there are multiple vulnerabilities in the libxslt package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For versions prior to 22.0.1229.79, update to version 22.0.1229.79 or later to resolve the issue. As a temporary workaround, consider restricting the use of XSL transforms until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02885
CESA-2012_1265
CVE-2012-2893
DSA-2555-1
OPENSUSE-SU-2012_1376-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:1265
RHSA-2012_1265

Produtos afetados

Centos
Google Chrome
Red Hat
Suse
Libxslt