Описание
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | not-affected | no webkit |
| devel | not-affected | 4.5.2-0ubuntu5 |
| hardy | not-affected | no webkit |
| intrepid | released | 4.4.3-0ubuntu1.4 |
| jaunty | not-affected | 4.5.0-0ubuntu4.2 |
| karmic | not-affected | 4.5.2-0ubuntu5 |
| lucid | not-affected | 4.5.2-0ubuntu5 |
| maverick | not-affected | 4.5.2-0ubuntu5 |
| natty | not-affected | 4.5.2-0ubuntu5 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | not-affected | 1.1.12-1ubuntu1 |
| hardy | ignored | end of life |
| intrepid | not-affected | 1.0.1-2ubuntu0.1 |
| jaunty | not-affected | 1.0.1-4 |
| karmic | not-affected | 1.1.12-1ubuntu1 |
| lucid | not-affected | 1.1.12-1ubuntu1 |
| maverick | not-affected | 1.1.12-1ubuntu1 |
| natty | not-affected | 1.1.12-1ubuntu1 |
| upstream | needs-triage |
Показывать по
EPSS
7.1 High
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0 ...
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
7.1 High
CVSS2
7.5 High
CVSS3