LWN.net Logo

xmlsec1: remote overwrite of arbitrary files

Package(s):xmlsec1 CVE #(s):CVE-2011-1425
Created:April 4, 2011 Updated:May 5, 2011
Description: From the Mandriva advisory:

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Alerts:
Debian DSA-2219-1 2011-04-18
Mandriva MDVSA-2011:063 2011-04-04
CentOS CESA-2011:0486 2011-05-05
CentOS CESA-2011:0486 2011-05-05
Red Hat RHSA-2011:0486-01 2011-05-04
Pardus 2011-73 2011-05-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds