Lucene search

K
ubuntuUbuntuUSN-633-1
HistoryAug 01, 2008 - 12:00 a.m.

libxslt vulnerabilities

2008-08-0100:00:00
ubuntu.com
43

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.18

Percentile

96.2%

Releases

  • Ubuntu 8.04
  • Ubuntu 7.10
  • Ubuntu 7.04
  • Ubuntu 6.06

Packages

  • libxslt -

Details

It was discovered that long transformation matches in libxslt could
overflow. If an attacker were able to make an application linked against
libxslt process malicious XSL style sheet input, they could execute
arbitrary code with user privileges or cause the application to crash,
leading to a denial of serivce. (CVE-2008-1767)

Chris Evans discovered that the RC4 processing code in libxslt did not
correctly handle corrupted key information. If a remote attacker were
able to make an application linked against libxslt process malicious
XML input, they could crash the application, leading to a denial of
service. (CVE-2008-2935)

OSVersionArchitecturePackageVersionFilename
Ubuntu8.04noarchlibxslt1.1<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu8.04noarchlibxslt1-dbg<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu8.04noarchlibxslt1-dev<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu8.04noarchpython-libxslt1<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu8.04noarchpython-libxslt1-dbg<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu8.04noarchxsltproc<Β 1.1.22-1ubuntu1.2UNKNOWN
Ubuntu7.10noarchlibxslt1.1<Β 1.1.21-2ubuntu2.2UNKNOWN
Ubuntu7.10noarchlibxslt1-dbg<Β 1.1.21-2ubuntu2.2UNKNOWN
Ubuntu7.10noarchlibxslt1-dev<Β 1.1.21-2ubuntu2.2UNKNOWN
Ubuntu7.10noarchpython-libxslt1<Β 1.1.21-2ubuntu2.2UNKNOWN
Rows per page:
1-10 of 221

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.18

Percentile

96.2%