Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1425

Опубликовано: 31 мар. 2011
Источник: redhat
CVSS2: 5.1

Описание

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=692133xmlsec1: arbitrary file creation when verifying signatures

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

nvd
почти 15 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

debian
почти 15 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in ...

github
больше 3 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

oracle-oval
почти 15 лет назад

ELSA-2011-0486: xmlsec1 security and bug fix update (MODERATE)

5.1 Medium

CVSS2