Lucene search

K
redhatRedHatRHSA-2008:0649
HistoryJul 31, 2008 - 12:00 a.m.

(RHSA-2008:0649) Moderate: libxslt security update

2008-07-3100:00:00
access.redhat.com
22

EPSS

0.18

Percentile

96.2%

libxslt is a library for transforming XML files into other XML files using
the standard XSLT stylesheet transformation mechanism.

A heap buffer overflow flaw was discovered in the RC4 libxslt library
extension. An attacker could create a malicious XSL file that would cause a
crash, or, possibly, execute arbitrary code with the privileges of the
application using the libxslt library to perform XSL transformations on
untrusted XSL style sheets. (CVE-2008-2935)

Red Hat would like to thank Chris Evans for reporting this vulnerability.

All libxslt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.