Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63qq-pm7h-vc34

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

EPSS

Процентиль: 92%
0.09609
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

redhat
около 14 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

nvd
около 14 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

debian
около 14 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in ...

oracle-oval
около 14 лет назад

ELSA-2011-0486: xmlsec1 security and bug fix update (MODERATE)

EPSS

Процентиль: 92%
0.09609
Низкий