LWN.net Logo

libxslt: code execution

Package(s):libxslt CVE #(s):CVE-2008-1767
Created:May 21, 2008 Updated:August 1, 2008
Description: From the Red Hat advisory: Anthony de Almeida Lopes reported the libxslt library did not properly process long "transformation match" conditions in the XSL stylesheet files. An attacker could create a malicious XSL file that would cause a crash, or, possibly, execute and arbitrary code with the privileges of the application using libxslt library to perform XSL transformations.
Alerts:
Ubuntu USN-633-1 2008-08-01
Mandriva MDVSA-2008:151 2007-07-21
Slackware SSA:2008-210-03 2008-07-29
SuSE SUSE-SR:2008:013 2008-06-13
Gentoo 200806-02 2008-06-03
CentOS CESA-2008:0287 2008-05-21
Red Hat RHSA-2008:0287-01 2008-05-21

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds