|
|
| |
|
| |
libxslt: code execution
| Package(s): | libxslt |
CVE #(s): | CVE-2008-1767
|
| Created: | May 21, 2008 |
Updated: | August 1, 2008 |
| Description: |
From the Red Hat advisory: Anthony de Almeida Lopes reported the libxslt library did not properly
process long "transformation match" conditions in the XSL stylesheet files.
An attacker could create a malicious XSL file that would cause a crash, or,
possibly, execute and arbitrary code with the privileges of the application
using libxslt library to perform XSL transformations. |
| Alerts: |
|
( Log in to post comments)
|
|
|