PT-2012-1042 · Libxslt+4 · Libxslt+4
Inferno
·
Published
2012-08-31
·
Updated
2024-06-15
·
CVE-2012-2893
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libxslt versions prior to 22.0.1229.79
Description
The issue is related to a double free vulnerability in libxslt, which can be exploited by remote attackers to cause a denial of service or possibly have other unspecified impacts. This is achieved through vectors related to XSL transforms. Additionally, there are multiple vulnerabilities in the libxslt package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations
For versions prior to 22.0.1229.79, update to version 22.0.1229.79 or later to resolve the issue. As a temporary workaround, consider restricting the use of XSL transforms until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Google Chrome
Red Hat
Suse
Libxslt