Описание
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | libxslt | Will not fix | ||
| Red Hat Enterprise Linux 6 | libxslt | Will not fix | ||
| Red Hat Enterprise Linux 7 | libxslt | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | libxslt | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | libxslt | Will not fix | ||
| Red Hat Gluster Storage 3.1 | libxslt | Will not fix | ||
| Red Hat OpenStack Platform 8 (Liberty) | libxslt | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) | libxslt | Will not fix | ||
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser | Fixed | RHSA-2016:1190 | 01.06.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51 ...
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
Уязвимость библиотеки XLST-преобразований LibXLST, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
EPSS
4.3 Medium
CVSS2