Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11068

Опубликовано: 10 апр. 2019
Источник: debian
EPSS Низкий

Описание

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxsltfixed1.1.32-2.1package
libxsltfixed1.1.32-2.1~deb10u1busterpackage
libxsltfixed1.1.29-2.1+deb9u1stretchpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libxslt/issues/12

  • https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6

EPSS

Процентиль: 77%
0.01109
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS3: 6.3
redhat
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS3: 9.8
nvd
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

suse-cvrf
около 6 лет назад

Security update for libxslt

suse-cvrf
около 6 лет назад

Security update for libxslt

EPSS

Процентиль: 77%
0.01109
Низкий