Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2935

Опубликовано: 01 авг. 2008
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5

Описание

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

РелизСтатусПримечание
dapper

released

1.1.15-1ubuntu1.1
devel

released

1.1.24-1ubuntu2
feisty

released

1.1.20-0ubuntu2.1
gutsy

released

1.1.21-2ubuntu2.1
hardy

released

1.1.22-1ubuntu1.1
upstream

released

1.1.25

Показывать по

EPSS

Процентиль: 95%
0.20676
Средний

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

nvd
почти 17 лет назад

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

debian
почти 17 лет назад

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka ex ...

github
около 3 лет назад

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

oracle-oval
почти 17 лет назад

ELSA-2008-0649: libxslt security update (MODERATE)

EPSS

Процентиль: 95%
0.20676
Средний

7.5 High

CVSS2