Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7995

Опубликовано: 26 авг. 2015
Источник: redhat
CVSS2: 5

Описание

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

A type confusion vulnerability was discovered in the xsltStylePreCompute() function of libxslt. A remote attacker could possibly exploit this flaw to cause an application using libxslt to crash by tricking the application into processing a specially crafted XSLT document.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxsltWill not fix
Red Hat Enterprise Linux 6libxsltWill not fix
Red Hat Enterprise Linux 7libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)libxsltWill not fix
Red Hat Enterprise MRG 2libxsltAffected
Red Hat Gluster Storage 3.1libxsltWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-587->CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=1257962libxslt: Type confusion may cause DoS

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

nvd
около 10 лет назад

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

debian
около 10 лет назад

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does n ...

github
больше 3 лет назад

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

suse-cvrf
больше 8 лет назад

Security update for libxslt

5 Medium

CVSS2