PT-2008-6893 · Libxslt+1 · Libxslt+1

Published

1970-01-01

·

Updated

2018-10-11

·

CVE-2008-2935

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxslt versions 1.1.8 through 1.1.24 libxslt-devel-1.1.11 libxslt-python-1.1.11 libxslt1-dev libxslt1-dbg libxslt1.1
Description The issue allows context-dependent attackers to execute arbitrary code via an XML file containing a long string as an argument in the XSL input, potentially leading to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations For libxslt versions 1.1.8 through 1.1.24, update to a version later than 1.1.24. For libxslt-devel-1.1.11, consider disabling the vulnerable package until a patch is available. For libxslt-python-1.1.11, restrict access to the package to minimize the risk of exploitation. For libxslt1-dev, libxslt1-dbg, and libxslt1.1, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for libxslt (до версии 1.1.24-r1) in Gentoo Linux.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01767
BDU:2015-01768
BDU:2015-01769
BDU:2015-07413
BDU:2015-07415
BDU:2015-07416
BDU:2015-08444
BDU:2015-08445
BDU:2015-08446
BDU:2015-09347
CVE-2008-2935
DSA-1624-1
DTSA-152-1
RHSA-2008:0649
RHSA-2008_0649

Affected Products

Red Hat
Libxslt