LWN.net Logo

libxslt: code execution

Package(s):libxslt CVE #(s):CVE-2012-2893
Created:October 4, 2012 Updated:October 22, 2012
Description:

From the Ubuntu advisory:

Cris Neckar discovered that libxslt incorrectly managed memory. If a user or automated system were tricked into processing a specially crafted XSLT document, a remote attacker could cause libxslt to crash, causing a denial of service, or possibly execute arbitrary code. (CVE-2012-2893)

Alerts:
Ubuntu USN-1595-1 2012-10-04
Debian DSA-2555-1 2012-10-05
Mageia MGASA-2012-0283 2012-10-06
Mandriva MDVSA-2012:164 2012-10-11
openSUSE openSUSE-SU-2012:1376-1 2012-10-22
Mandriva MDVSA-2013:047 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds