Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1202

Опубликовано: 11 мар. 2011
Источник: debian
EPSS Низкий

Описание

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxsltfixed1.1.26-7package
xulrunnerremovedpackage
xulrunnerno-dsalennypackage
iceweaselfixed3.5.19-1package
iceweaselno-dsasqueezepackage
iceweaselnot-affectedlennypackage
iceapefixed2.0.14-1package
iceapeno-dsasqueezepackage
iceapenot-affectedlennypackage
libxsltfixed1.1.26-6+squeeze1squeezepackage
libxsltno-dsalennypackage

Примечания

  • http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html

  • xulrunner in wheezy is not covered by security support

EPSS

Процентиль: 76%
0.0102
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

redhat
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

nvd
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

github
около 3 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

oracle-oval
почти 13 лет назад

ELSA-2012-1265: libxslt security update (IMPORTANT)

EPSS

Процентиль: 76%
0.0102
Низкий