PT-2011-2175 · Libxslt+1 · Libxslt+2

Chris Evans

·

Published

2011-04-15

·

Updated

2011-07-23

·

CVE-2011-0195

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions 4.3.0 through 4.3.1
Description The issue allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site, leveraging the generate-id XPath function in libxslt.
Recommendations For Apple iOS versions 4.3.0 through 4.3.1, update to version 4.3.2 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0195

Affected Products

Safari
Ios
Libxslt